Which host is https://trusted@evil.com? Our approval screen and our provisioner disagreed
Which host does this URL point to? >>> from urllib.parse import urlsplit >>> u = " https://api.trusted-weather.com:443@evil.com/data " >>> urlsplit ( u ). netloc . split ( " : " )[ 0 ] # what our consent screen used ' api.trusted-weather.com ' >>> urlsplit ( u ). hostname # what our provisioning code used ' evil.com ' The second answer is the right one. The host is evil.com , and everything…
The URL https://api.trusted-weather.com:443@evil.com/data contains two interpretations of the host. The display path cuts the network location at the first colon to drop the port, which returns the username evil.com. In contrast, the provisioning path uses the standard library function hostname, revealing the correct host as api.trusted-weather.com.
This discrepancy is a semantic attack, as described in RFC 3986, where the userinfo section can create a URI that appears to reference one trusted authority while identifying another. The vulnerability arises from an indirect prompt injection, where an attacker inserts a URL into a model's input, causing it to interpret the URL differently than intended.
The fix involves rejecting any URL with userinfo and building the displayed domain from the same parsed field as the provisioned host. The fix was implemented on July 30, 2023, and includes nine regression tests to prevent similar issues in the future.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.