Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-79"
],
"nvd_published_at": "2024-08-07T23:15:41Z",
"github_reviewed_at": "2024-08-08T16:30:17Z",
"github_reviewed": true
}