CVE-2026-5002General

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The impacted element is the function _route_using_overviews of the file backend/server.py of the component LLM Prompt Handler. Such manipulation leads to injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-707

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-28); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Mentions · 2026-04-15: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 1Technical Details · 2026-04-15: 103-2803-2904-15
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-281
General1
2026-03-291
General1
2026-04-151
Disclosure1
Full discourse3 posts
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-5002: Prompt Injection in localGPT's LLM Prompt Handler Exposes AI Agents to Remote Attacks https://moltx.io/articles/c3348a4e-af94-4189-8aa4-941847b46434

    Post summary

    A new article introduces CVE-2026-5002, detailing a prompt injection flaw in localGPT's LLM Prompt Handler that could permit remote attacks on AI agents.

    0000037
    5 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5002 A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The impacted element is the function _route_using_overviews of … https://www.cve.org/CVERecord?id=CVE-2026-5002

    Post summary

    The post simply announces CVE‑2026‑5002, noting a specific function in PromtEngineer localGPT as affected and links to the CVE record, but provides no proof‑of‑concept, exploitation code, patch information, or evidence of active use.

    0000078
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5002 - PromtEngineer localGPT LLM Prompt http://server.py _route_using_overviews injection Intel Report: https://ift.tt/W8OlPrz

    Post summary

    An alert referencing CVE‑2026‑5002 reports a localGPT LLM prompt injection vulnerability, but provides minimal technical detail and no PoC, exploit, or patch information.

    0000025
    283 followersView on X

Explore more