ThreatCluster

Critical Prompt Injection Vulnerability Affects AI in CI/CD Pipelines

First seen 6 Dec 2025, 20:46 UTC CsoonlineCybersecuritynews 72% similarity 20

Article Content

Browse articles
ThreatCluster

Researchers have identified a critical vulnerability class named 'PromptPwnd' that affects AI agents in GitHub Actions and GitLab CI/CD pipelines. This vulnerability allows attackers to inject malicious prompts through untrusted user inputs, leading to the execution of privileged commands that can leak sensitive information. At least five Fortune 500 companies, including Google, have been impacted by this flaw.

ThreatCluster AI

Community

Browse all →