{
  "id": 8041279,
  "title": "A Prompt Injection Turned Into a Shell: Inside Semantic Kernel's Two RCE CVEs",
  "url": "https://urgent.news/2026/09/17/a-prompt-injection-turned-into-a-shell-inside-semantic-kernels-two",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-17T14:36:35.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/aditya_soni_e5b9d5213e544/a-prompt-injection-turned-into-a-shell-inside-semantic-kernels-two-rce-cves-22l7"
  },
  "original_language": "en",
  "account": null,
  "summary": "Two ordinary agent-framework conveniences, a filterable vector search and a file-download tool, turned into remote code execution once an LLM's output was trusted a little too much. Here's what happened in Microsoft Semantic Kernel, and what to check in your own agent code today. Prompt injection usually gets discussed as an output-quality problem: the model says something it shouldn't, or does…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}