Database/AI/ML frameworks & serving
Decepticon: unfiltered ChatML special tokens in crawl results give a target page control of the agent
Impact
Decepticon feeds web reconnaissance output into LLM messages without neutralizing ChatML special-token literals. A string planted in a page the agent crawls therefore forges an operator turn that the model treats as authoritative, bypassing the agent's guardrails and running attacker-chosen commands inside its Kali sandbox. The part that generalizes beyond this one tool is the deployment assumption: the advisory notes that vLLM, SGLang, Ollama, LM Studio and text-generation-webui do not strip special-token literals from user content in their default configurations, so any self-hosted inference endpoint on a GPU fleet will happily parse those literals into real role-boundary token IDs for whatever application calls it. Operators running their own OpenAI-compatible endpoints should treat role-boundary sanitization as the caller's job and audit their own agents for the same gap. Affects Decepticon before 1.1.17.
Who can reach it
Anyone who controls content the agent is pointed at - a web page in the target scope. No authentication and no prior access to the host running the agent; the operator only has to run reconnaissance against the attacker's content.
What to do
Upgrade decepticon-core / decepticon-sdk to 1.1.17 and restart the agent - a package upgrade, no node drain. Separately, and more consequentially for a fleet: inventory anything that builds prompts from untrusted text against your self-hosted vLLM or SGLang endpoints, and filter ChatML special-token literals out of user content at the caller, since the inference servers will not do it by default. Treat the agent's sandbox as untrusted and keep its network reach and credentials narrow.
References
Related entries
- ClearML web server: XSSCVE-2024-24594 · ClearML web serverCritical
- Red Hat OpenShift AI (notebook plane): A low-privileged data-scientist account can escalate to full cluster compromiseCVE-2025-10725 · Red Hat OpenShift AI (notebook plane)Critical
- BentoML (file upload): SSRF in the file-upload pathCVE-2025-54381 · BentoML (file upload)Critical
- OpenShift AI MaaS API: any in-cluster pod forges identity headers to impersonate tenantsCVE-2026-14450 · Red Hat OpenShift AI MaaS API (Kuadrant AuthPolicy gateway)Critical
- NVIDIA OpenShell: incomplete input denylist in the sandbox provisioning API allows code executionCVE-2026-65083 · NVIDIA OpenShell (sandbox provisioning API)Critical
- NVIDIA OpenShell: sandbox escape lets confined code run outside the sandboxCVE-2026-65093 · NVIDIA OpenShell (agent sandbox confinement)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.