Microsoft (Microsoft Defender Security Research Team)
aidefend-sf0004
Prompt-to-Shell: Dual RCE Paths in Microsoft Semantic Kernel
- Autonomous Agents
- Tool Integrations & MCP
- System Compromise & RCE
- Resource Hijacking & Cost
Microsoft documented two distinct Semantic Kernel prompt-to-host-RCE paths: a Python Search Plugin filter evaluated with eval(), and a .NET SessionsPythonPlugin file-transfer function exposed to model tool calling that could write a payload into the host Startup folder.