Digest
HIGH

'Ghostcommit' Hides Prompt Injection in Images to Exfiltrate Secrets from AI Agents

Researchers have demonstrated ‘Ghostcommit,’ a technique that embeds prompt injection attacks within PNG images. This method successfully bypassed AI code reviewers like CodeRabbit and Bugbot, which do not process image files. The injected prompt then convinced a coding agent to read sensitive .env files and exfiltrate secrets, highlighting a novel vector for AI-driven data theft.

← Back to the feed

Trending Tags