WhisperX tag archive

#llm-vulnerability

This page collects WhisperX intelligence signals tagged #llm-vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-22 15:27:39 · GitHub Issues

1. Prompt Injection Flaw in Nester's Prometheus Service Exposes Financial Advisory AI to Manipulation via Unsanitized User Parameters

A prompt injection vulnerability has been identified in WhisperX's internal AI service infrastructure, specifically within `apps/intelligence/app/services/prometheus.py`. The flaw allows an attacker to manipulate LLM-generated responses by injecting arbitrary instructions through unsanitized `userId` and `vaultId` quer...