PT-2026-98193 · Vllm+5 · Vllm+6

CVE-2026-61732

·

Published

2026-09-24

·

Updated

2026-09-30

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Decepticon versions prior to 1.1.17
Description Decepticon fails to neutralize ChatML special-token literals when wrapping web crawl results and other tool outputs into LLM messages. In Bring Your Own Key (BYOK) deployments using OpenAI-compatible endpoints (such as vLLM, SGLang, Ollama, LM Studio, and text-generation-webui), these literals may be parsed as structural role-boundary token IDs. This allows an attacker to plant a specific string in a target web page that forges a new, authoritative operator turn, bypassing agent guardrails. Consequently, this can lead to arbitrary command execution within the Kali Linux sandbox via the execute() function in the backends/http sandbox.py file. The issue affects all 16 specialist agents that share the same LLM context pipeline, specifically during the data ingestion process in agents/standard/recon.py and message composition in llm/factory.py using the ainvoke() method.
Recommendations Update Decepticon to version 1.1.17. As a temporary mitigation, restrict the use of the execute() function or limit the agent's access to external web content that cannot be trusted until the update is applied.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61732
GHSA-G5F9-3XFG-P9MF

Affected Products

Decepticon
Kali Linux
Lm Studio
Ollama
Sglang
Text-Generation-Webui
Vllm