AWS, 구글, Vercel의 보안 결함으로 공격자가 모델을 실행하지 않고 도구를 트리거할 수 있음.
AWS, 구글, Vercel의 에이전트 인프라에서 보안 결함이 발견되어 신뢰할 수 없는 지시가 에이전트 도구에 도달할 수 있는 문제가 발생했습니다. 이 공격 경로에서는 모델이 전혀 실행되지 않아 시스템 프롬프트, 콘텐츠 필터 및 모델 수준의 가드레일이 개입할 기회를 잃었습니다. 이러한 취약점은 다양한 제품에 영향을 미치고 있습니다.
Security flaws in AWS, Google, and Vercel allow attackers to trigger tools without running the model.
Security vulnerabilities in the agent infrastructure of AWS, Google, and Vercel have been discovered, allowing untrusted instructions to reach an agent's tools unchecked. In several attack paths, the model did not run at all, which means that system prompts, content filters, and model-level guardrails had no chance to intervene. These vulnerabilities affect multiple products.