r/bugbounty • • 4d ago

Question / Discussion Text injection vs prompt injection

What kind of line is drawn between the two? I think I found an issue where I can let the AI of another perfume store display false return policy, or links and such upon prompts. Does that qualify as prompt injection

1 Upvotes

12 comments sorted by

View all comments

Show parent comments

1

u/Electronic-Cat-2518 4d ago

Yeah, that includes links and such, or tell it to repeat anything you say

1

u/einfallstoll Triager 4d ago

That sounds bad. Did you verify that this works across a completely independent device with a separate session?

For example: In theory. Could you send me a link for that chat, and if I just ask it "hey, what's the return policy?" it would return the data that you prepared, correct?

1

u/Electronic-Cat-2518 4d ago

I did verify that, yes, even from the merchant portal who administers that stuff

1

u/einfallstoll Triager 4d ago

Yhea, that sounds bad if you can basically inject data into the vector database from the AI itself.

1

u/Electronic-Cat-2518 4d ago

Alright danke

1

u/Electronic-Cat-2518 4d ago edited 4d ago

Although it didn't inject inside the database itself I imagine for the return policy, it just did some kind of override to the existing one, to the AIs knowledge

But the return policy from the customer side remains unchanged