
Connect it to a file system, a shell, or an API, and the threat model inverts. A prompt injection becomes a control-flow hijack. Think of CVE-2023-32786, where a malicious doc in a LangChain agent could execute arbitrary code through its file-reading tool.
Post summary
The text references CVE‑2023‑32786, noting that a malicious document in a LangChain agent’s file‑reading tool can lead to arbitrary code execution, but does not mention a PoC, exploit code, active exploitation, or a patch.

