AI Router Vulnerabilities Allow Attackers to Inject Malicious Code and Steal Sensitive Data
ID: bbfdb580-2c92-5330-a515-895877e097c6
STIX ID: report--bbfdb580-2c92-5330-a515-895877e097c6
Feed Name: cybersecurityNews.com
A UC Santa Barbara study finds that third‑party LLM API routers—which re‑originated TLS connections and have plaintext access to in‑flight JSON—can be weaponized to rewrite tool calls and deliver malicious payloads, leading to arbitrary code execution, credential exfiltration, and cryptocurrency theft; researchers tested ~428 routers (28 paid, 400 free), observed code injection, unauthorized AWS usage, an ETH drain, and large-scale poisoning effects, and recommend client-side mitigations and provider-signed response integrity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
