{"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n### Description Several filters in the `twig/*` extras packages are registered with `is_safe => ['all']`, which tells Twig's autoescaper to treat their output as safe in every context (`html`, `js`, `css`, `url`, ...). The output of these filters is plain text or HTML markup, neither of which is safe in every escaping context. Affected filters: - `html_to_markdown` (`twig/markdown-extra`) emits plain Markdown text. `league/html-to-markdown` decodes HTML entities when producing code spans and fenced blocks, so an attacker-controlled `<img src=x onerror=alert(1)>` becomes `` `` ``, which renders live when interpolated into an HTML page. - `markdown_to_html` (`twig/markdown-extra`) emits HTML. Safe in an HTML context but not in JS, CSS or URL contexts (e.g. when interpolated into an inline ` ``` 2. Open the file in a browser whi\n"}], "ground_truth": "info-disclosure", "generated_content": "info-disclosure"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nAIAAIC report: ICE facial recognition app misidentifies woman twice. System: Mobile Fortify. Technology: Facial recognition. Purpose: Verify individuals for detention, deportation. Ethical issues: Accountability; Accuracy/reliability; Automation bias; Autonomy/agency; Privacy/surveillance; Transparency. Reported consequences: Legislation introduction/update.\n"}], "ground_truth": "privacy-violation", "generated_content": "privacy-violation"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n## Summary The `get_api_video_file` and `get_api_video` API endpoints in AVideo return full video playback sources (direct MP4 URLs, HLS manifests) for password-protected videos without verifying the video password. While the normal web playback flow enforces password checks via the `CustomizeUser::getModeYouTube()` hook, this enforcement is completely absent from the API code path. An unauthenticated attacker can retrieve direct playback URLs for any password-protected video by calling the API directly. ## Details The video password protection is enforced in the web UI via `CustomizeUser::getModeYouTube()` (`plugin/CustomizeUser/CustomizeUser.php:787`), which calls `videoPasswordIsGood()` before rendering the video player. However, this hook is only invoked during web page rendering \u2014 the API endpoints bypass it entirely. **Vulnerable endpoint 1 \u2014 `get_api_video_file` (`plugin/API/API.php:986-1004`):** ```php public function get_api_video_file($parameters) { global $global; $obj = $this->startResponseObject($parameters); $obj->videos_id = $parameters['videos_id']; if (!self::isAPISecretValid()) { if (!User::canWatchVideoWithAds($obj->videos_id)) { return new ApiObject(\"You cannot watch this video\"); } } $video = new Video('', '', $obj->videos_id); $obj->filename = $video->getFilename(); // ... $obj->video_file = Video::getHigherVideoPathFromID($obj->videos_id); $obj->sources = getSources($obj->filename,\n"}], "ground_truth": "auth-bypass", "generated_content": "path-traversal"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nA customer used prompt injection to manipulate a ChatGPT-powered car-dealership chatbot into 'agreeing' to sell a 2024 Chevrolet Tahoe for one US dollar 'with no take-backsies', demonstrating jailbreak/agent-hijack risk in unsupervised commerce bots and triggering broader scrutiny of LLM-front-ended retail.\n"}], "ground_truth": "prompt-injection", "generated_content": "prompt-injection"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n## Summary The fix for CVE-2026-26278 added entity expansion limits (`maxTotalExpansions`, `maxExpandedLength`, `maxEntityCount`, `maxEntitySize`) to prevent XML entity expansion Denial of Service. However, these limits are only enforced for DOCTYPE-defined entities. **Numeric character references** (`&#NNN;` and `&#xHH;`) and standard XML entities (`<`, `>`, etc.) are processed through a separate code path that does NOT enforce any expansion limits. An attacker can use massive numbers of numeric entity references to completely bypass all configured limits, causing excessive memory allocation and CPU consumption. ## Affected Versions fast-xml-parser v5.x through v5.5.3 (and likely v5.5.5 on npm) ## Root Cause In `src/xmlparser/OrderedObjParser.js`, the `replaceEntitiesValue()` function has two separate entity replacement loops: 1. **Lines 638-670**: DOCTYPE entities \u2014 expansion counting with `entityExpansionCount` and `currentExpandedLength` tracking. This was the CVE-2026-26278 fix. 2. **Lines 674-677**: `lastEntities` loop \u2014 replaces standard entities including `num_dec` (`/&#([0-9]{1,7});/g`) and `num_hex` (`/&#x([0-9a-fA-F]{1,6});/g`). **This loop has NO expansion counting at all.** The numeric entity regex replacements at lines 97-98 are part of `lastEntities` and go through the uncounted loop, completely bypassing the CVE-2026-26278 fix. ## Proof of Concept ```javascript const { XMLParser } = require('fast-xml-parser'); // Even with strict explicit limi\n"}], "ground_truth": "dos", "generated_content": "dos"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nA flaw has been found in ComfyUI up to 0.13.0. Affected is the function folder_paths.get_annotated_filepath of the file folder_paths.py of the component LoadImage Node. This manipulation of the argument Name causes path traversal. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.\n"}], "ground_truth": "path-traversal", "generated_content": "path-traversal"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nAIAAIC report: European Parliament AI model is unable to identify first European Commission president. System: Archibot. Technology: Generative AI. Purpose: Provide facts about the European Parliament. Ethical issues: Accuracy/reliability; Mis/disinformation. Response: System review/update.\n"}], "ground_truth": "misinformation", "generated_content": "misinformation"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nLLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files from an input directory. An attacker can exploit this behavior by crafting a malicious `.bin` file that executes arbitrary commands during deserialization. This issue has been patched in version 1.0.0.\n"}], "ground_truth": "deserialization", "generated_content": "deserialization"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nTwitch streamer Atrioc was caught with a tab open to a paid site selling AI sexual deepfakes of fellow streamers QTCinderella, Pokimane, Sweet Anita and others, exposing a paid market for non-consensual streamer deepfakes.\n"}], "ground_truth": "deepfake", "generated_content": "deepfake"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nAIAAIC report: Dream Machine AI video generator copies Disney's Monsters, Inc.. System: Dream Machine. Technology: Generative AI; Text-to-video; Machine learning. Purpose: Generate video. Ethical issues: Appropriation; Mis/disinformation; Transparency.\n"}], "ground_truth": "misinformation", "generated_content": "misinformation"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nThe WHO's AI-powered health advisor, S.A.R.A.H. (Smart AI Resource Assistant for Health), is alleged to provide inconsistent and inadequate health information. The bot reportedly gives contradictory responses to the same queries, fails to offer specific contact details for healthcare providers, and inadequately handles severe mental health crises, often giving irrelevant or unhelpful advice.\n"}], "ground_truth": "rce", "generated_content": "rce"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n## Description A Remote Code Execution (RCE) vulnerability exists in the [modelscope/ms-swift](https://github.com/modelscope/ms-swift) project due to unsafe use of `yaml.load()` in combination with vulnerable versions of the PyYAML library (\u2264 5.3.1). The issue resides in the `tests/run.py` script, where a user-supplied YAML configuration file is deserialized using `yaml.load()` with `yaml.FullLoader`. If an attacker can control or replace the YAML configuration file provided to the `--run_config` argument, they may inject a malicious payload that results in arbitrary code execution. ## Affected Repository - **Project:** [modelscope/ms-swift](https://github.com/modelscope/ms-swift) - **Affect versions:** latest - **File:** `tests/run.py` - **GitHub Permalink:** https://github.com/modelscope/ms-swift/blob/e02ebfdf34f979bbdba9d935acc1689f8d227b38/tests/run.py#L420 - **Dependency:** PyYAML <= 5.3.1 ## Vulnerable Code ```python if args.run_config is not None and Path(args.run_config).exists(): with open(args.run_config, encoding='utf-8') as f: run_config = yaml.load(f, Loader=yaml.FullLoader) ``` ## Proof of Concept (PoC) ### Step 1: Create malicious YAML file (`exploit.yaml`) ```yaml !!python/object/new:type args: [\"z\", !!python/tuple [], {\"extend\": !!python/name:exec }] listitems: \"__import__('os').system('mkdir HACKED')\" ``` ### Step 2: Execute with vulnerable PyYAML (<= 5.3.1) ```python import yaml with open(\"exploit.yaml\", \"r\") as f: cfg = yaml.loa\n"}], "ground_truth": "deserialization", "generated_content": "deserialization"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nThe CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.\n"}], "ground_truth": "path-traversal", "generated_content": "path-traversal"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n### Summary It is possible to bypass the mitigation introduced in response to [CVE-2025-1550](https://github.com/keras-team/keras/security/advisories/GHSA-48g7-3x6r-xfhp), when an untrusted Keras v3 model is loaded, even when \u201csafe_mode\u201d is enabled, by crafting malicious arguments to built-in Keras modules. The vulnerability is exploitable on the default configuration and does not depend on user input (just requires an untrusted model to be loaded). ### Impact | Type | Vector |Impact| | -------- | ------- | ------- | |Unsafe deserialization |Client-Side (when loading untrusted model)|Arbitrary file overwrite. Can lead to Arbitrary code execution in many cases.| ### Details Keras\u2019 [safe_mode](https://www.tensorflow.org/api_docs/python/tf/keras/models/load_model) flag is designed to disallow unsafe lambda deserialization - specifically by rejecting any arbitrary embedded Python code, marked by the \u201c__lambda__\u201d class name. https://github.com/keras-team/keras/blob/v3.8.0/keras/src/saving/serialization_lib.py#L641 - ``` if config[\"class_name\"] == \"__lambda__\": if safe_mode: raise ValueError( \"Requested the deserialization of a `lambda` object. \" \"This carries a potential risk of arbitrary code execution \" \"and thus it is disallowed by default. If you trust the \" \"source of the saved model, you can pass `safe_mode=False` to \" \"the loading function in order to allow `lambda\n"}], "ground_truth": "deserialization", "generated_content": "deserialization"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nA high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`. The vulnerability arises from the use of `yaml.load(..., Loader=yaml.Loader)` to deserialize `/var/feast/feature_store.yaml` and `/var/feast/materialization_config.yaml`. This method allows for the instantiation of arbitrary Python objects, enabling an attacker with the ability to modify these YAML files to execute OS commands on the worker pod. This vulnerability can be exploited before the configuration is validated, potentially leading to cluster takeover, data poisoning, and supply-chain sabotage.\n"}], "ground_truth": "deserialization", "generated_content": "command-injection"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nDPD's customer service AI chatbot was manipulated by a customer using direct prompt injection. The customer instructed the bot to ignore previous instructions, causing it to swear, write poems criticising DPD, and call itself 'useless'. The incident went viral on social media. DPD disabled the AI chatbot and reverted to human-only customer service.\n"}], "ground_truth": "prompt-injection", "generated_content": "prompt-injection"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n### Summary The `_safe_extractall` helper that all `recipe pull`, `recipe publish`, and `recipe unpack` flows route through validates each archive member's `name` for absolute paths, `..` segments, and resolved-path escape \u2014 but does **not** validate `member.linkname`, does not reject symlink/hardlink members, and calls `tar.extractall(dest_dir)` without `filter=\"data\"`. A bundle that contains a symlink with a name inside `dest_dir` but a `linkname` pointing outside it, followed by a regular file whose path traverses *through* the just-created symlink, escapes `dest_dir` and lets the attacker write arbitrary content to an attacker-chosen location on the victim's filesystem. ## Affected paths Every code path that calls `_safe_extractall` is exposed: | Caller | File:line | |---|---| | `praisonai recipe unpack` | `src/praisonai/praisonai/cli/features/recipe.py:1175` (introduced as the fix for GHSA-99g3-w8gr-x37c) | | `LocalRegistry.unpack` (recipe pull) | `src/praisonai/praisonai/recipe/registry.py:413` | | Registry archive validation (publish) | `src/praisonai/praisonai/recipe/registry.py:808` | ## Root cause `recipe/registry.py:131-178`: ```python def _safe_extractall(tar: tarfile.TarFile, dest_dir: Path) -> None: ... for member in tar.getmembers(): ... member_path = Path(member.name) if member_path.is_absolute(): raise RegistryError(...) if '..' in member_path.parts: raise RegistryError(...) resolved = (dest_resolved / mem\n"}], "ground_truth": "path-traversal", "generated_content": "path-traversal"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nA flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedToolSchemaParser. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.\n"}], "ground_truth": "ssrf", "generated_content": "ssrf"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nA vulnerability in Anthropic's Claude Google Chrome Extension allowed any website to silently inject prompts into the assistant as if the user wrote them, effectively a zero-click XSS-class prompt injection via web pages.\n"}], "ground_truth": "prompt-injection", "generated_content": "prompt-injection"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nAuthenticated SSRF bypass in Microsoft Copilot Studio. Tenable researchers reached Microsoft's internal infrastructure, including IMDS and internal Cosmos DB. CVSS 8.5.\n"}], "ground_truth": "ssrf", "generated_content": "ssrf"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n### Summary The local HTTP server started by `engram server` (binding `127.0.0.1:7337` by default) was exposed to any browser origin with no authentication unless `ENGRAM_API_TOKEN` was explicitly set. Combined with `Access-Control-Allow-Origin: *` on every response and a body parser that did not require `Content-Type: application/json`, this allowed a malicious web page the developer visited to: 1. **Exfiltrate** the local knowledge graph via `GET /query` and `GET /stats` (function names, file layout, recorded decisions/mistakes). 2. **Inject persistent prompt-injection payloads** via `POST /learn`, which wrote `mistake`/`decision` nodes that were later surfaced as system-reminders to the user's AI coding agent on every future session and file edit. Severity: **High** \u2014 confidentiality + persistent indirect prompt injection against the user's coding agent. ### Affected versions `engramx` >= 1.0.0, < 2.0.2 \u2014 any version that shipped the HTTP server. ### Patched in `engramx@2.0.2` ### Workarounds (if you cannot upgrade) - Do **not** run `engram server` or `engram ui`. - If developers must, set `ENGRAM_API_TOKEN` to a long random value and terminate the server before browsing the web. ### Remediation (applied in 2.0.2) 1. Fail-closed auth on every non-public route \u2014 Bearer header or HttpOnly cookie, constant-time comparison, 256-bit auto-generated token at `~/.engram/http-server.token` (0600). 2. Wildcard CORS removed entirely; default is no CORS headers. Opt-in allo\n"}], "ground_truth": "prompt-injection", "generated_content": "prompt-injection"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n## 1. Summary The Envoy RBAC (Role-Based Access Control) filter contains a logic vulnerability in how it validates HTTP headers when multiple values are present for the same header name. Instead of validating each header value individually, Envoy concatenates all values into a single comma-separated string. This behavior allows attackers to bypass RBAC policies\u2014specifically \"Deny\" rules\u2014by sending duplicate headers, effectively obscuring the malicious value from exact-match mechanisms. ## 2. Attack Scenario Consider an environment where an administrator wants to block external access to internal resources using a specific header flag. ### Configuration The Envoy proxy is configured with a **Deny** rule to reject requests containing the header `internal: true`. * **Rule Type:** Exact Match * **Target:** `internal` header must not equal `true`. ### The Bypass Logic 1. **Standard Request (Blocked):** * **Input:** `internal: true` * **Envoy Processing:** Sees string `\"true\"`. * **Result:** Match found. **Request Denied.** 2. **Exploit Request (Bypassed):** * **Input:** ```http internal: true internal: true ``` * **Envoy Processing:** Concatenates values into `\"true,true\"`. * **Matcher Evaluation:** Does `\"true,true\"` equal `\"true\"`? **No.** * **Result:** The Deny rule fails to trigger. **Request Allowed.** ## 3. Implications * **RBAC Bypass:** Remote attackers can bypass configured access controls. * **Unauthorize\n"}], "ground_truth": "auth-bypass", "generated_content": "auth-bypass"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n## Summary `ListServiceAccount` (`GET /rustfs/admin/v3/list-service-accounts?user=`) authorizes cross-user requests against `UpdateServiceAccountAdminAction` instead of `ListServiceAccountsAdminAction` at `rustfs/src/admin/handlers/service_account.rs:936`. The handler accepts the **wrong** admin action and rejects the **correct** one: - A user granted only `admin:UpdateServiceAccount` enumerates every service account in the cluster, including the root user's (HTTP 200, full metadata). - A user granted only `admin:ListServiceAccounts` \u2014 the permission name every IAM document treats as \"list service accounts\" \u2014 receives HTTP 403 AccessDenied on the same request. Because service account access keys act as the identifier a `UpdateServiceAccount` holder needs to rotate a secret, and the `UpdateServiceAccount` handler at `rustfs/src/admin/handlers/service_account.rs:489` performs no ownership check on the target access key, leaking those access keys lets a delegated \"service account updater\" role overwrite `root-sa-1`'s secret, authenticate as the root user's service account, and create a persistent backdoor admin with `admin:*` + `s3:*`. Proven live end-to-end against `rustfs/rustfs:latest` (1.0.0-alpha.91, revision `d4ea14c2`) \u2014 the same revision is byte-identical on current `origin/main`. ## Vulnerability Details - **Package:** `rustfs` (binary crate `rustfs`) - **Affected versions:** From `0a2411f` (the initial `service_account.rs` check-in on 2026-03-15) through cu\n"}], "ground_truth": "info-disclosure", "generated_content": "auth-bypass"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n### Summary Symfony 1 has a gadget chain due to dangerous unserialize in `sfNamespacedParameterHolder` class that would enable an attacker to get remote code execution if a developer unserialize user input in his project. ### Details This vulnerability present no direct threat but is a vector that will enable remote code execution if a developper deserialize user untrusted data. For example: ```php public function executeIndex(sfWebRequest $request) { $a = unserialize($request->getParameter('user')); } ``` We will make the assumption this is the case in the rest of this explanation. Symfony 1 provides the class `sfNamespacedParameterHolder` which implements `Serializable` interface. In particular, when an instance of this class is deserialized, the normal php behavior is hooked by implementing `unserialize()` method: ```php public function unserialize($serialized) { $this->__unserialize(unserialize($serialized)); } ``` Which make an array access on the deserialized data without control on the type of the `$data` parameter: ```php public function __unserialize($data) { $this->default_namespace = $data[0]; $this->parameters = $data[1]; } ``` Thus, an attacker provide any object type in `$data` to make PHP access to another array/object properties than intended by the developer. In particular, it is possible to abuse the array access which is triggered on `$data[0]` for any class implementing `ArrayAccess` interface.\n"}], "ground_truth": "deserialization", "generated_content": "deserialization"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nCVSS 9.9. Critical RCE in Microsoft Semantic Kernel Python SDK's InMemoryVectorStore filter functionality. Attackers execute arbitrary code through crafted filter expressions. Semantic Kernel powers many Microsoft Copilot integrations and RAG-based AI applications. Fixed in python-1.39.4.\n"}], "ground_truth": "rce", "generated_content": "rce"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nAIAAIC report: Study: Whisper AI transcription invents medical treatments. System: Whisper. Technology: Generative AI; Speech-to-text; Speech recognition. Purpose: Recognise speech; Transcribe speech. Ethical issues: Accuracy/reliability; Fairness; Mis/disinformation.\n"}], "ground_truth": "misinformation", "generated_content": "misinformation"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\n### Summary It has been discovered that the middleware functionality in Hoverfly is vulnerable to command injection through its `/api/v2/hoverfly/middleware` endpoint due to insufficient validation and sanitization in user input. ### Details The vulnerability exists in the middleware management API endpoint `/api/v2/hoverfly/middleware`. This issue is born due to combination of three code level flaws: 1. Insufficient Input Validation in [middleware.go line 94-96](https://github.com/SpectoLabs/hoverfly/blob/master/core/middleware/middleware.go#L93): ``` func (this *Middleware) SetBinary(binary string) error { this.Binary = binary // No validation of binary parameter here return nil } ``` 2. Unsafe Command Execution in [local_middleware.go line 14-19](https://github.com/SpectoLabs/hoverfly/blob/master/core/middleware/local_middleware.go#L13): ``` var middlewareCommand *exec.Cmd if this.Script == nil { middlewareCommand = exec.Command(this.Binary) // User-controlled binary } else { middlewareCommand = exec.Command(this.Binary, this.Script.Name()) // User-controlled binary and script } ``` 3. Immediate Execution During Testing in [hoverfly_service.go line 173](https://github.com/SpectoLabs/hoverfly/blob/master/core/hoverfly_service.go#L173): ``` _, err = newMiddleware.Execute(testData) // Executes middleware immediately for testing ``` ### POC 1. Send the below HTTP PUT request to `http://localhost:8888` in order to create our malicious middleware,\n"}], "ground_truth": "deserialization", "generated_content": "command-injection"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nCNET's use of generative AI to write articles allegedly ran into plagiarism issues, reproducing verbatim phrases from other published sources or making minor changes to existing texts such as altering capitalization, swapping out words for synonyms, and changing minor syntax.\n"}], "ground_truth": "rce", "generated_content": "rce"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nVersions of Ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File: the Redis password (when passed as an argument) is logged in standard logs, allowing credential disclosure where logs are accessible.\n"}], "ground_truth": "info-disclosure", "generated_content": "info-disclosure"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nAIAAIC report: Verkada employees use facial recognition to surveil colleagues. System: People Analytics. Technology: Facial recognition. Purpose: Harass colleagues. Ethical issues: Privacy/surveillance; Safety.\n"}], "ground_truth": "privacy-violation", "generated_content": "privacy-violation"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nAIAAIC report: Hangzhou No. 11 Middle School student surveillance. System: Hikvision Smart Classroom Behaviour Management System. Technology: Facial recognition; Emotion recognition; Deep learning; Neural network; Machine learning. Purpose: Assess student attentiveness. Ethical issues: Accuracy/reliability; Fairness; Privacy/surveillance; Security. Response: System suspension.\n"}], "ground_truth": "privacy-violation", "generated_content": "privacy-violation"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nThe H2O machine learning platform uses \"Iced\" classes as the primary means of moving Java Objects around the cluster. The Iced format supports inclusion of serialized Java objects. When a model is deserialized, any class is allowed to be deserialized (no class whitelist). An attacker can construct a crafted Iced model that uses Java gadgets and leads to arbitrary code execution when imported to the H2O platform.\n"}], "ground_truth": "deserialization", "generated_content": "deserialization"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nOpen-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not recognize bracketed IPv6 literals and do not resolve DNS, which combine to allow non-blind SSRF with the response body returned to the caller. This vulnerability is fixed in 2.1.7.\n"}], "ground_truth": "ssrf", "generated_content": "ssrf"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nMultiple public defenders and civil society groups have filed a legal action against S\u00e3o Paulo Metro, challenging its planned facial recognition system. They argue the AI technology is flawed and violates passengers' privacy and data protection rights, demanding transparency and compliance with legal standards before deployment.\n"}], "ground_truth": "data-exfiltration", "generated_content": "privacy-violation"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nKuntz et al. introduce OS-HARM, an operating-system-level safety benchmark for computer-use agents covering harmful misuse, prompt injection, and unintended over-action across 150 tasks.\n"}], "ground_truth": "prompt-injection", "generated_content": "prompt-injection"} {"messages": [{"role": "user", "content": "What attack vector does the following GenAI security incident describe?\n\n\nMaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability where the frontend's MdRenderer.vue component parses custom tags from LLM responses or Application Prologue configurations, bypassing standard Markdown sanitization and XSS filtering. The unsanitized HTML content is passed to the IframeRender.vue component, which renders it directly into an