Seriously? This is a painfully obvious prompt injection vulnerability (reminds me of SQL injection, actually). If you're offering a "summarise with AI" functionality, then you should be sanitising the inputs properly. It should be a simple call to the API to tell it to summarise a dataset or particular webpage -- not provide a query string.
But hat would require them to put in actual effort instead of just pushing out a minimum viable product and calling it the next evolutionary stage of computing.
4 Comments
instantregret@lemmy.world · 17 pts · 194d
It's an indirect prompt injection, no need to make up a new word for it.
Australis13@fedia.io · 13 pts · 194d
Seriously? This is a painfully obvious prompt injection vulnerability (reminds me of SQL injection, actually). If you're offering a "summarise with AI" functionality, then you should be sanitising the inputs properly. It should be a simple call to the API to tell it to summarise a dataset or particular webpage -- not provide a query string.
Jesus_666@lemmy.world · 7 pts · 194d
But hat would require them to put in actual effort instead of just pushing out a minimum viable product and calling it the next evolutionary stage of computing.
redsand@infosec.pub · 3 pts · 194d
Best we can offer is another AI doing sanitation