LLM Data Exfiltration: No JavaScript, Just an Image
LLM data exfiltration needs no script and no click. A markdown image is a silent outbound GET, and my own password reached my server in the query string.
3 write-ups tagged Content Security Policy. Browse all tags or the full blog.
LLM data exfiltration needs no script and no click. A markdown image is a silent outbound GET, and my own password reached my server in the query string.
Insecure output handling mitigations, layer by layer. Every LLM attack in this track dies to a control invented before LLMs, and the sandbox moves least.
Insecure output handling in LLM apps: the model refused my XSS payload and the page still fired an alert. Reflected and stored LLM XSS, from a real lab run.