CWE-1427— Improper Neutralization of Input Used for LLM Prompting
The product uses externally-provided data to build prompts provided to large language models (LLMs), but the way these prompts are constructed causes the LLM to fail to distinguish between user-supplied inputs and developer provided system directives.— MITRE CWE catalog
8 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1427page 1 of 1
- CVE-2026-15077MEDIUMCVSS 4.3EG 4.32026-07-29
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due t…
- CVE-2026-18733HIGHCVSS 8.8EG 8.82026-08-03
A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive …
- CVE-2026-21832MEDIUMCVSS 4.3EG 4.32026-08-13
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain…
- CVE-2026-44688HIGHCVSS 8.8EG 8.82026-06-18
In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository wi…
- CVE-2026-46580HIGHCVSS 8.8EG 8.82026-06-18
In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious reposi…
- CVE-2026-70331MEDIUMCVSS 5.4EG 5.42026-08-28
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-75130CRITICALCVSS 9.0EG 9.02026-08-18
Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via t…
- CVE-2026-78379HIGHCVSS 8.1EG 8.12026-08-25
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate,…
Map vulnerabilities like CWE-1427 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1427 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →