Critical Prompt Injection Vulnerability Affects AI in CI/CD Pipelines
First seen 6 Dec 2025, 20:46 UTC
•
•72% similarity
•20
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Researchers have identified a critical vulnerability class named 'PromptPwnd' that affects AI agents in GitHub Actions and GitLab CI/CD pipelines. This vulnerability allows attackers to inject malicious prompts through untrusted user inputs, leading to the execution of privileged commands that can leak sensitive information. At least five Fortune 500 companies, including Google, have been impacted by this flaw.
ThreatCluster AI