Executive brief
promptr is a command-line tool that loads prompts and templates from URLs to interact with OpenAI's GPT models. An attacker can host a malicious prompt file on a web server and trick users into loading it; the prompt can instruct GPT to perform arbitrary file operations (create, read, update, delete) on the user's system, leading to unauthorized file modification or data theft.
Technical details
The vulnerability is a prompt injection flaw (CWE-94) in promptr v6.0.7 that allows remote command execution through maliciously crafted prompts loaded from attacker-controlled URLs. The application fetches prompt and template files from HTTP/HTTPS URLs without validation and passes them directly to OpenAI's GPT model. An attacker can embed function-calling instructions in the prompt to invoke the "crud_operations" function (create, read, update, delete files) that promptr exposes to GPT. The attack vector is network-based and requires user interaction—a victim must run promptr with an attacker-supplied URL argument. The impact is high: an attacker can read, modify, or delete arbitrary files on the user's system, such as SSH keys or configuration files. A patch is needed to sanitize prompts or disable file operation functions when loading untrusted prompts.
Affected products
- ferrislucas promptr 6.0.7 and earlier
Timeline
- 2024-09-25: disclosed: Public disclosure via GHSA and NVD