FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Ghostcommit: Image-Embedded Prompt Injection Bypassing AI Code Review

Ghostcommit exploits steganographic embedding of malicious prompt instructions within image files to subvert AI‑driven code‑review pipelines that invoke vision‑language models (e.g., GPT‑4V, Claude 3 Vision). When the model processes the image via OCR or direct vision input, the hidden text is interpreted as part of the prompt, overriding safety filters and forcing the model to disclose secrets such as API keys, SSH private keys, or .env contents. The attack evades conventional text‑based sanitization and file‑type checks, enabling data exfiltration through model output or logged review comments.


LINK COPIED TO CLIPBOARD