Threat Advisory

Decepticon ChatML Injection Vulnerability

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-61732 (CVSS 10.0 – Critical): A role-boundary forgery vulnerability allows attacker-controlled web content containing ChatML special-token literals to manipulate LLM message boundaries. When Decepticon uses a BYOK OpenAI-compatible backend whose tokenizer preserves these special tokens, the injected content can bypass agent guardrails and trigger attacker-chosen command execution in the Kali Linux sandbox.

RECOMMENDATION:

We recommend you to update Decepticon to version 1.1.17.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-61732 (CVSS 10.0 – Critical): A role-boundary forgery vulnerability allows attacker-controlled web content containing ChatML special-token literals to manipulate LLM message boundaries. When Decepticon uses a BYOK OpenAI-compatible backend whose tokenizer preserves these special tokens, the injected content can bypass agent guardrails and trigger attacker-chosen command execution in the Kali Linux sandbox.

RECOMMENDATION:

We recommend you to update Decepticon to version 1.1.17.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu