YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0062

Incident record

Agent data injection corrupts the data AI agents trust, across major assistants

Severity
High
Status
Proof-of-concept
Type
Prompt Injection
Target
AI agents
Actor
researcher

What happened

Researchers from Seoul National University, the University of Illinois Urbana-Champaign and Largosoft disclosed agent data injection, a technique that corrupts the factual data AI agents read rather than hiding explicit instructions, causing agents to take unintended actions such as unwanted purchases or running attacker commands. They demonstrated it against web and coding agents including Anthropic's Claude in Chrome and Claude Code, OpenAI's Codex, Google's Antigravity and Gemini CLI, and Nanobrowser. OpenAI, Google and Anthropic acknowledged the reports; Nanobrowser did not respond, and the researchers say no fix has been shipped or announced.

The demonstrations run from a poisoned product review that forges the element identifier of a Buy Now button, so the agent completes a purchase the user never asked for while still doing the real task of summarising reviews, through to remote code execution and supply-chain attacks against coding agents. The same attack failed against ChatGPT Atlas, which randomises the identifier it gives each page element at runtime, leaving an attacker no identifier to forge.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026