Preliminary research
No Tools Required: Post-Injection Exploitation Across AI Agent Frameworks
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Prompt injection is the given; the bugs are in the framework underneath. A tool-call argument carrying LangChain's own constructor JSON is revived by its loader into a chat model with an attacker endpoint and a secret placeholder filled from env vars; Microsoft Agent Framework checkpoints decode __af_dataclass__ into any class with attacker kwargs; CrewAI's RAG tools accept a path or URL, giving file read, SSRF, and a crash in MuPDF's overflowed image unpacker.
Record
- Researcher
- Yarden Porat and Shahar Tal
- Published by
- i.blackhat.com
- Format
- Whitepaper
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Yarden Porat and Shahar Tal, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .