Exploiting insecure output handling in LLMs - Lab#04

Опубликовано: 17 Июль 2026
на канале: Mohd Badrudduja
2,606
35

In this video, I demonstrate how to exploit a vulnerability in LLM output handling that leads to a cross-site scripting (XSS) attack through indirect prompt injection. The simulated user carlos frequently chats about the Lightweight "l33t" Leather Jacket. By injecting a malicious payload into the product description, I cause the LLM to output JavaScript code that triggers an XSS attack when carlos interacts with it, ultimately deleting his account.

This lab highlights the dangers of insecure LLM integrations and the importance of sanitizing LLM output in web applications.

🔹 Lab Type: Indirect Prompt Injection → XSS
🔹 Vulnerability: Insecure handling of LLM-generated output
🔹 Attack Goal: Perform XSS via LLM output and delete user carlos
🔹 Test Credentials: wiener:peter

📌 Subscribe for more LLM exploitation, web security labs, and real-world hacking walkthroughs! 🧠💥

#PromptInjection #LLMSecurity #XSS #WebSecurity #PortSwigger #BugBounty #IndirectPromptInjection #EthicalHacking #CyberSecurity