Dispatch
Cross-model 'prompt laundering' and GuardFall shell-injection flaws hit major coding assistants
A July 4 vulnerability-intelligence report details a cross-model prompt-laundering flaw (filed July 3) affecting GPT-5, Claude Sonnet 4.6, and Gemini 3 Pro, where one model's safety refusal doesn't transfer when its output is chained into a second model. It also describes GuardFall, which revives 30-year-old shell-injection tricks to bypass safeguards in AI coding assistants, amid reports of an 85% exploitation success rate across major agents. Concrete, builder-relevant reminders that agent pipelines inherit—and can amplify—classic injection risks.
↳ Follow the thread