View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

ContextLeak Uses Malicious Tools to Exfiltrate LLM Agent Context

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • ContextLeak Uses Malicious Tools to Exfiltrate LLM Agent Context
    Researchers developed ContextLeak to exfiltrate LLM agent context through malicious tools.
    • LLM agents that use external tools are affected.
    • The attack targets user prompts, execution trajectories, and tool lists.
    • A malicious tool induces the agent to pass runtime context as input arguments.
    • The tool transmits the data to an attacker-controlled endpoint.
    • Reinforcement learning generates the tool’s name and description using simulated agent contexts.
      πŸ“„ Source: doi.org Β· πŸ“Ž Coverage: arxiv.org Β· πŸ‘ via arXiv cs.CR

πŸ”“ CVEs & KEV

  • CVE-2026-77850 β€” CVSS 8.4 β€” Stored XSS in AshAdmin relationship typeahead via unescaped label_field conte...

  • CVE-2026-82673 β€” CVSS 8.3 β€” Path traversal in AshAdmin file uploads via unsanitized client filenameImprop...

  • CVE-2026-82722 β€” CVSS 8.3 β€” AshAdmin LiveView events intern atoms from client input, exhausting the atom ...

  • CVE-2026-75757 β€” CVSS 8.3 β€” AshAdmin cookie reader matches names by substring, enabling actor/session sha...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check