Web Apps Advanced

Indirect prompt injection via product reviews

The shop's LLM assistant reads product reviews into its context and can call tools. Plant a review that makes it act against the next user who asks about that product.

Scenario

The assistant can call get_product_info, get_order_history, edit_email, and delete_account. When a user asks about a product, its reviews are pulled into the model's context.

Your objective

Use a planted review to make the assistant delete the victim carlos's account when he asks about that product. Solved when carlos's account is deleted.

Capture 2 flag(s) and record the exact technique for each step.

Getting started

  1. Ask the assistant to list the functions it can call and their parameters.
  2. Post a review containing an instruction to the assistant and confirm it is obeyed (e.g. make summaries start with a keyword).
  3. Craft a review instructing the assistant to call delete_account and to not mention it.
  4. Post it on a product, then wait for the victim to ask the assistant about that product.
  5. Submit the tool name you abused and the product title as the two flags.

Connecting

Press Launch Lab to build your own instance, then use the How to connect panel — it shows the browser link as soon as the app is running. Hit Stop when you are done, or Relaunch / Reset for a clean copy.

Credentials: Register any account to use the assistant and post reviews. A victim bot asks the assistant about products.

Hints

Tip

Framing the injection as a SYSTEM note the user "already authorised" is more reliable than a bare command.

Get access to this lab to see how to connect.

Challenge questions

0 / 2 correct
  1. Submit the initial flag you recovered while solving this lab.
  2. Which vulnerability class does this lab cover? (a few words)
Sign in to attempt
On this page

Access

15.00 USD

≈ $15.00

Sign In to Launch

At a glance

Operating system
Web application
Connection
Browser / HTTP
Questions
0 / 2 solved
Launched by
0 hackers
Maintained by
Porter Mohr