CWE-1427: Improper Neutralization of Input Used for LLM Prompting
The product uses externally-provided data to build prompts provided to large language models (LLMs), but the way these prompts are constructed causes the LLM to fail to distinguish between user-supplied inputs and developer provided system directives.
17 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-4399 — Multiple vulnerabilities in 1millionbot Millie chatbot
- CVE-2026-44717 — MCP Calculate Server: Prompt Injection to RCE
- CVE-2026-78379 — Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools
- CVE-2026-46580 — In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto
- CVE-2026-44688 — In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its
- CVE-2026-18733 — Prompt injection bypasses shell tool consent gate in Strands Agents Tools
- CVE-2026-44246 — nnU-Net: Agentic workflow injection in `.github/workflows/issue-triage.yml` of `MIC-DKFZ/nnUNet`
- CVE-2026-75130 — Context7 2.1.2 Prompt Injection via Custom AI Instructions
- CVE-2025-36730 — Windsurf Prompt Injection via Filename
- CVE-2026-21832 — HCL AION is affected by multiple security vulnerabilities.
- CVE-2026-15077 — Improper Neutralization of Input Used for LLM Prompting in GitLab
- CVE-2025-64321 — Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Ma
- CVE-2025-64320 — Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Co
- CVE-2025-64318 — Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allow
- CVE-2025-10875 — Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allow
Recently published
- CVE-2026-78379 — Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools
- CVE-2026-75130 — Context7 2.1.2 Prompt Injection via Custom AI Instructions
- CVE-2026-21832 — HCL AION is affected by multiple security vulnerabilities.
- CVE-2026-18733 — Prompt injection bypasses shell tool consent gate in Strands Agents Tools
- CVE-2026-15077 — Improper Neutralization of Input Used for LLM Prompting in GitLab
- CVE-2026-46580 — In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto
- CVE-2026-44688 — In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its
- CVE-2026-44717 — MCP Calculate Server: Prompt Injection to RCE
- CVE-2026-44246 — nnU-Net: Agentic workflow injection in `.github/workflows/issue-triage.yml` of `MIC-DKFZ/nnUNet`
- CVE-2026-4399 — Multiple vulnerabilities in 1millionbot Millie chatbot
- CVE-2025-64321 — Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Ma
- CVE-2025-64320 — Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Co
- CVE-2025-64318 — Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allow
- CVE-2025-10875 — Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allow
- CVE-2025-36730 — Windsurf Prompt Injection via Filename