Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.
{
"nvd_published_at": "2024-08-07T23:15:41Z",
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-08-08T16:30:17Z"
}