What If Prompt Injection Never Left? Rethinking Agent Security through Cross-Session Stored Prompt Injection
Researchers have identified a security vulnerability in agentic AI systems where malicious instructions can persist across multiple user sessions. Because modern agents utilize long-term memory, filesystems, and tool access, a single prompt injection can embed itself into the system state to compromise future interactions. This findings highlight a shift in security risks, moving from transient input attacks to persistent threats that could allow attackers to maintain control over an agent's long-term behavior or stored data.
Covered by 1 source
- AarXiv CS.AI↗Yuanbo Xie, Wenlei Zhu, Tianyun Liu, Yingjie Zhang, Suchen Liu, Yulin Li, Liya Su, Tingwen Liu1d ago