Submit #623100: zlt2000 https://github.com/zlt2000/microservices-platform <=6.0.0 Unrestricted Upload of File with Dangerous Type (CWE-434) [Accepted]
Submit #623100 / VDB-319375
Today we have another post about OpenHands from All Hands AI. It is a popular agent, initially named “OpenDevin”, and recently the company also provides a cloud-based service. Which is all pretty cool and exciting.
Prompt Injection to Full System CompromiseHowever, as you know, LLM powered apps and agents are vulnerable to prompt injection. That also applies to OpenHands and it can be hijacked by untrusted data, e.g. from a website. That impacts Confidentiality, Integrity, and Availability of the system.