A Prompt Injection Turned Into a Shell: Inside Semantic Kernel's Two RCE CVEs
Two ordinary agent-framework conveniences, a filterable vector search and a file-download tool, turned into remote code execution once an LLM's output was trusted a little too much. Here's what happened in Microsoft Semantic Kernel, and what to check in your own agent code today. Prompt injection usually gets discussed as an output-quality problem: the model says something it shouldn't, or does…
We haven't written up this one. Dev.to has the full story — the link below goes straight to it.