PT-2026-98193 · Vllm+5 · Vllm+6
CVE-2026-61732
·
Published
2026-09-24
·
Updated
2026-09-30
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Decepticon versions prior to 1.1.17
Description
Decepticon fails to neutralize ChatML special-token literals when wrapping web crawl results and other tool outputs into LLM messages. In Bring Your Own Key (BYOK) deployments using OpenAI-compatible endpoints (such as vLLM, SGLang, Ollama, LM Studio, and text-generation-webui), these literals may be parsed as structural role-boundary token IDs. This allows an attacker to plant a specific string in a target web page that forges a new, authoritative operator turn, bypassing agent guardrails. Consequently, this can lead to arbitrary command execution within the Kali Linux sandbox via the
execute() function in the backends/http sandbox.py file. The issue affects all 16 specialist agents that share the same LLM context pipeline, specifically during the data ingestion process in agents/standard/recon.py and message composition in llm/factory.py using the ainvoke() method.Recommendations
Update Decepticon to version 1.1.17.
As a temporary mitigation, restrict the use of the
execute() function or limit the agent's access to external web content that cannot be trusted until the update is applied.Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Decepticon
Kali Linux
Lm Studio
Ollama
Sglang
Text-Generation-Webui
Vllm