Opening SecureFlowLLMSmith: RCE Vulnerabilities in LLM-Integrated Applications
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

MITRE ATLAS mitre-atlas-cs0052

LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications

  • Autonomous Agents
  • System Compromise & RCE

Researchers identified 20 remote code execution (RCE) vulnerabilities across 11 different LLM frameworks. They discovered applications deployed on the public internet built using these LLM frameworks and demonstrated the RCE vulnerabilities could be exploited using prompt injection. The 11 LLM frameworks the researchers evaluated were: LangChain, LlamaIndex, Pandas-ai, Langflow, Pandas-llm, Auto-GPT, Griptape, Lagent, MetaGPT, vanna, and langroid.

Mapped threat techniques

Source

Updated