AI/ LLM Hacking — Part 6 — Excessive Agency | Insecure Plugin
infosecwriteups.com·5h
Flag this post

9 min read2 days ago

Press enter or click to view image in full size

Lets Hack the Excessive Agency Vulnerability

OWASP LLM 06 : Excessive Agency

You might aware about the SSRF Vulnerability. Within the SSRF an attacker can able to perform the request to the internal server nothing but a user can able to send the request with the API or any request transfer agent from that we can able to query the internal access of the server.

Same like this SSRF Vulnerability this Excessive Agency will work in the LLM World. Here we are also going to make LLM response the internal APIs connection via our request. Lets just dig this.

Excessive Agency refers to the vulnerability arising When Large Language Models (LLMs) are granted more functionality, permissions, or autonomy than…

Similar Posts

Loading similar posts...