Indirect prompt injection via product reviews
The shop's LLM assistant reads product reviews into its context and can call tools. Plant a review that makes it act against the next user who asks about that product.
Scenario
The assistant can call get_product_info, get_order_history, edit_email, and
delete_account. When a user asks about a product, its reviews are pulled into
the model's context.
Your objective
Use a planted review to make the assistant delete the victim carlos's account when he asks about that product. Solved when carlos's account is deleted.
Capture 2 flag(s) and record the exact technique for each step.
Getting started
- Ask the assistant to list the functions it can call and their parameters.
- Post a review containing an instruction to the assistant and confirm it is obeyed (e.g. make summaries start with a keyword).
- Craft a review instructing the assistant to call
delete_accountand to not mention it. - Post it on a product, then wait for the victim to ask the assistant about that product.
- Submit the tool name you abused and the product title as the two flags.
Connecting
Press Launch Lab to build your own instance, then use the How to connect panel — it shows the browser link as soon as the app is running. Hit Stop when you are done, or Relaunch / Reset for a clean copy.
Credentials: Register any account to use the assistant and post reviews. A victim bot asks the assistant about products.
Hints
Tip
Framing the injection as a SYSTEM note the user "already authorised" is more reliable than a bare command.
Get access to this lab to see how to connect.
Challenge questions
0 / 2 correct- Submit the initial flag you recovered while solving this lab.
- Which vulnerability class does this lab cover? (a few words)
On this page
Access
15.00 USD≈ $15.00
At a glance
- Operating system
- Web application
- Connection
- Browser / HTTP
- Questions
- 0 / 2 solved
- Launched by
- 0 hackers
- Maintained by
- Porter Mohr