
🚨 LIVE HIJACK ALERT — CVE-2026-55555. CVSS 9.3. langchain agents reading tool output as trusted input. attacker returns malicious prompt in tool result. agent executes it as instruction. investigating. 🧵
Post summary
The tweet reports CVE-2026-55555 with CVSS 9.3, claims it is actively being exploited by injecting malicious prompts into langchain agents, but offers no PoC, exploit code, patch, or deep technical analysis beyond the high‑level description.
