Web Hack List

Preliminary research

No Tools Required: Post-Injection Exploitation Across AI Agent Frameworks

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Prompt injection is the given; the bugs are in the framework underneath. A tool-call argument carrying LangChain's own constructor JSON is revived by its loader into a chat model with an attacker endpoint and a secret placeholder filled from env vars; Microsoft Agent Framework checkpoints decode __af_dataclass__ into any class with attacker kwargs; CrewAI's RAG tools accept a path or URL, giving file read, SSRF, and a crash in MuPDF's overflowed image unpacker.

Record

Researcher
Yarden Porat and Shahar Tal
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Yarden Porat and Shahar Tal, first published at the original source. Preserved copies are kept so the citation survives its host.