Banking AI Agent Vulnerable to XSS via Payment Reference

TL;DR. A banking AI agent demonstrated vulnerabilities to Cross-Site Scripting (XSS) and indirect prompt injection through payment references. - Attackers could compromise user sessions by embedding malicious code in transaction details or PDF documents. - The vulnerability exploits how the AI agent processes and displays user-generated content, leading to unauthorized access. - This highlights risks in AI systems that handle sensitive financial data and interact with external inputs.

Sources

Back to QLANKR News