GPU VulnDB

Database/AI/ML frameworks & serving

Decepticon: unfiltered ChatML special tokens in crawl results give a target page control of the agent

CVSS 10.0CVE-2026-61732AI/ML frameworks & servingcurated

Impact

Decepticon feeds web reconnaissance output into LLM messages without neutralizing ChatML special-token literals. A string planted in a page the agent crawls therefore forges an operator turn that the model treats as authoritative, bypassing the agent's guardrails and running attacker-chosen commands inside its Kali sandbox. The part that generalizes beyond this one tool is the deployment assumption: the advisory notes that vLLM, SGLang, Ollama, LM Studio and text-generation-webui do not strip special-token literals from user content in their default configurations, so any self-hosted inference endpoint on a GPU fleet will happily parse those literals into real role-boundary token IDs for whatever application calls it. Operators running their own OpenAI-compatible endpoints should treat role-boundary sanitization as the caller's job and audit their own agents for the same gap. Affects Decepticon before 1.1.17.

Who can reach it

Anyone who controls content the agent is pointed at - a web page in the target scope. No authentication and no prior access to the host running the agent; the operator only has to run reconnaissance against the attacker's content.

What to do

Upgrade decepticon-core / decepticon-sdk to 1.1.17 and restart the agent - a package upgrade, no node drain. Separately, and more consequentially for a fleet: inventory anything that builds prompts from untrusted text against your self-hosted vLLM or SGLang endpoints, and filter ChatML special-token literals out of user content at the caller, since the inference servers will not do it by default. Treat the agent's sandbox as untrusted and keep its network reach and credentials narrow.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.