Banks 使用一个简单的模板语言生成具有实际意义的 LLM 提示词。在版本 2.5.0 之前,Banks 的 Prompt.chat_messages() 方法会尝试将渲染后的模板输出中的每一行解析为 ChatMessage JSON 对象。当应用程序渲染不可信数据,并将返回的 ChatMessage 对象传递给大语言模型(LLM)提供商时,攻击者控制的 JSON 数据可能突破提示词边界,伪装成系统消息、助手消息或工具消息,因为 ChatMessage.role 字段接受任意字符串。这可能导致覆盖应用预设的系统指
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet