logo

Cross Session Leak: LLM security vulnerability & detection guide

ID: 0a936dff-05e4-540b-90b2-e04ed6f7a8c5

STIX ID: report--0a936dff-05e4-540b-90b2-e04ed6f7a8c5

Feed Name: Giskard

Threat Score
70/100

Date Published: 2025-10-16

Date Updated: 2026-07-28

...
...

**Cross-session leak**: the report explains how failures in session isolation and shared caching in multi-user LLM systems can cause sensitive data from one user session (e.g., PHI) to be returned to another user, demonstrated with a healthcare telemedicine assistant case where an attacker obtained patient records through social engineering. It describes detection via dynamic red-teaming probes, preventive controls (per-user isolation, output redaction, access controls, logging, and monitoring), and recommends architectural safeguards and continuous security validation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.