CVE-2026-61732

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals. Under the BYOK (Bring Your Own Key) deployment model, users configure their own LLM credentials to any OpenAI-compatible endpoint. Most open-source and self-deployed model providers (vLLM, SGLang, Ollama, LM Studio, text-generation-webui, etc.) do not filter special-token literals from user content in their default configurations. Those literals are parsed into structural role-boundary token IDs, meaning an attacker string planted in a target web page forges a new operator turn the model treats as authoritative, bypassing Decepticon's agent guardrails and resulting in arbitrary command execution inside the Kali Linux sandbox. Version 1.1.17 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 3 mentions (2026-09-25); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-09-25: 3Mentions · 2026-09-26: 109-2509-26
Referenced assets2 URLs
Full discourse4 posts
  • Ryx@PadhiyarRushi

    Plant ChatML tokens in a web page! Decepticon’s crawler forges an operator turn and runs your command in Kali! CVE-2026-61732 / GHSA-g5f9-3xfg-p9mf (CVSS 10.0), published Sept 24. Crawl output is wrapped into LLM messages with no special-token neutralization. On BYOK endpoints (vLLM, SGLang, Ollama, LM Studio) those literals become real role-boundary IDs. Guardrails drop. Arbitrary commands in the agent sandbox. Lab repo reproduces the chain. Fixed in 1.1.17. https://github.com/BitterSecurity/Decepticon/security/advisories/GHSA-g5f9-3xfg-p9mf #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #LLMSecurity #Agents #RCE

    11021137
    924 followersView on X
  • ExploitGrid@exploitgrid

    [CVE] CVE-2026-61732 [HIGH PRIORITY] #Decepticon: Role-boundary forgery via ChatML special-token literals in web cr... 🔗 https://exploitgrid.net/cve/CVE-2026-61732

    1001028
    47 followersView on X
  • ExploitGrid@exploitgrid

    🟠 HIGH PRIORITY ├ CVE-2026-97359 — HFS2 2.4.0 · RCE via multipart upload template injection ├ CVE-2026-97360 — HFS2 2.4.0 · Unauth arbitrary file read/write ├ CVE-2026-61732 — Decepticon · Role-boundary forgery via ChatML tokens

    1000033
    47 followersView on X
  • ExploitGrid@exploitgrid

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-61732 CVE-2026-97359 CVE-2026-97360 CVE-2026-19072 CVE-2026-93425 ..🧵👇

    1000038
    47 followersView on X

Explore more