<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Prompt-Injection — PoC Archive</title><link>https://poc.intelseclab.com/tags/prompt-injection/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/prompt-injection/index.xml" rel="self" type="application/rss+xml"/><item><title>Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2026-27966-langflow-mass-scanner/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2026-27966-langflow-mass-scanner/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-27966 (GHSA-3645-fxcv-hqr4). Status: Patched. Affects: Langflow (langflow-ai). Tags: langflow, rce, pre-auth, route-injection, vertex-injection, csv-agent, prompt-injection, python, mass-scanner, ai-security.</description><category>web</category><category>Critical</category><category>langflow</category><category>rce</category><category>pre-auth</category><category>route-injection</category><category>vertex-injection</category><category>csv-agent</category><category>prompt-injection</category><category>python</category><category>mass-scanner</category><category>ai-security</category></item><item><title>Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-26030-semantic-kernel-eval-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-26030-semantic-kernel-eval-rce/</guid><description>Critical severity — misc · CVE-2026-26030. Status: Weaponized. Affects: Microsoft Semantic Kernel (Python), InMemoryCollection vector store connector. Tags: semantic-kernel, python, eval-injection, sandbox-bypass, prompt-injection, llm-agent, rce, ast-allowlist-bypass, vector-store.</description><category>misc</category><category>Critical</category><category>semantic-kernel</category><category>python</category><category>eval-injection</category><category>sandbox-bypass</category><category>prompt-injection</category><category>llm-agent</category><category>rce</category><category>ast-allowlist-bypass</category><category>vector-store</category></item><item><title>Claude Code WebFetch Hardcoded HuggingFace Bare-Hostname Allow-List Bypass — CVE-2026-54316</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-54316-claude-code-webfetch-hf-exfil/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-54316-claude-code-webfetch-hf-exfil/</guid><description>Medium severity — misc · CVE-2026-54316 (GHSA-fg94-h982-f3mm). Status: PoC. Affects: @anthropic-ai/claude-code (npm package, Claude Code CLI). Tags: claude-code, webfetch, prompt-injection, exfiltration, huggingface, allow-list-bypass, agentic-ai, docker-lab, cwe-183.</description><category>misc</category><category>Medium</category><category>claude-code</category><category>webfetch</category><category>prompt-injection</category><category>exfiltration</category><category>huggingface</category><category>allow-list-bypass</category><category>agentic-ai</category><category>docker-lab</category><category>cwe-183</category></item><item><title>adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33980-adx-mcp-server-kql-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33980-adx-mcp-server-kql-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-33980. Status: PoC. Affects: adx-mcp-server (pab1it0/adx-mcp-server). Tags: mcp, kql-injection, azure-data-explorer, ai-agent, prompt-injection, cwe-943, data-exfiltration.</description><category>web</category><category>High</category><category>mcp</category><category>kql-injection</category><category>azure-data-explorer</category><category>ai-agent</category><category>prompt-injection</category><category>cwe-943</category><category>data-exfiltration</category></item><item><title>Firefox Smart Window Private URL Exfiltration</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_firefox-smartwindow-private-url-exfil/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_firefox-smartwindow-private-url-exfil/</guid><description>High severity — web · None assigned as of 2026-07-03. Status: PoC. Affects: Firefox Smart Window (AI browsing assistant feature). Tags: firefox, smart-window, ai-assistant, privacy-leak, information-disclosure, url-token-exfiltration, browser, prompt-injection.</description><category>web</category><category>High</category><category>firefox</category><category>smart-window</category><category>ai-assistant</category><category>privacy-leak</category><category>information-disclosure</category><category>url-token-exfiltration</category><category>browser</category><category>prompt-injection</category></item></channel></rss>