Web Hack List

Preliminary research

No Tools Required: Post-Injection Exploitation Across AI Agent Frameworks

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Prompt injection is the given; the bugs are in the framework underneath. A tool-call argument carrying LangChain's own constructor JSON is revived by its loader into a chat model with an attacker endpoint and a secret placeholder filled from env vars; Microsoft Agent Framework checkpoints decode __af_dataclass__ into any class with attacker kwargs; CrewAI's RAG tools accept a path or URL, giving file read, SSRF, and a crash in MuPDF's overflowed image unpacker.

Record

Researcher
Yarden Porat and Shahar Tal
Published by
i.blackhat.com
Format
Whitepaper
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Yarden Porat and Shahar Tal, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .