logo

Eurostar AI vulnerability: when a chatbot goes off the rails

ID: 38294b25-85e0-52bb-bd3b-400e830117e8

STIX ID: report--38294b25-85e0-52bb-bd3b-400e830117e8

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2025-12-22

Date Updated: 2026-03-24

Author: Alex Wallace

...
...

Researchers identified four vulnerabilities in Eurostar’s AI chatbot: guardrail bypass due to insufficient signature binding on chat history, prompt injection revealing model and system prompts, HTML injection leading to self-XSS, and unvalidated conversation/message IDs that risk replay or cross-user exposure. The report demonstrates the request/response mechanics behind the flaws, outlines potential escalation to stored/shared XSS, describes a problematic disclosure process despite a VDP, and recommends mitigations including strict server-side signature binding of messages and guard decisions, server-generated/validated IDs, robust input validation, and HTML output sanitization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.