
Plant ChatML tokens in a web page! Decepticon’s crawler forges an operator turn and runs your command in Kali! CVE-2026-61732 / GHSA-g5f9-3xfg-p9mf (CVSS 10.0), published Sept 24. Crawl output is wrapped into LLM messages with no special-token neutralization. On BYOK endpoints (vLLM, SGLang, Ollama, LM Studio) those literals become real role-boundary IDs. Guardrails drop. Arbitrary commands in the agent sandbox. Lab repo reproduces the chain. Fixed in 1.1.17. https://github.com/BitterSecurity/Decepticon/security/advisories/GHSA-g5f9-3xfg-p9mf #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #LLMSecurity #Agents #RCE

