VDB

GCVE-110-CLOUD-2024-0054

GCVE-110-CLOUD-2024-0054
Advisory Published
Vulnetix · Advisory published January 18, 2024
An Indirect Prompt Injection attack can cause the LLM to return markdown tags. This allows an adversary who’s data makes it into the chat context (e.g via an uploaded file) to achieve data exfiltration of the victim’s data by rendering hyperlinks.

Affected Products

VendorProductVersionsPlatforms
AWSCloud Services
AWSAmazon Q

References

advisory

Browse GCVE Records

73,873 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›