CVE-2026-61732
Last modified
CVE-2026-61732 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals.
Description
Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals. Under the BYOK (Bring Your Own Key) deployment model, users configure their own LLM credentials to any OpenAI-compatible endpoint. Most open-source and self-deployed model providers (vLLM, SGLang, Ollama, LM Studio, text-generation-webui, etc.) do not filter special-token literals from user content in their default configurations. Those literals are parsed into structural role-boundary token IDs, meaning an attacker string planted in a target web page forges a new operator turn the model treats as authoritative, bypassing Decepticon's agent guardrails and resulting in arbitrary command execution inside the Kali Linux sandbox. Version 1.1.17 patches the issue.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| BitterSecurity | Decepticon | < 1.1.17 |
| BitterSecurity | decepticon-core | < 1.1.17 |
| BitterSecurity | decepticon-sdk | < 1.1.17 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-61732?
How severe is CVE-2026-61732?
How do I fix CVE-2026-61732?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-61714FluidSynth is a software synthesizer based on the SoundFont …7.8
- CVE-2026-61718bunkerweb is an Open-source and next-generation Web Applicat…5.4
- CVE-2026-61720FluidSynth is a software synthesizer based on the SoundFont …6.2
- CVE-2026-61721FluidSynth is a software synthesizer based on the SoundFont …8
- CVE-2026-61722FluidSynth is a software synthesizer based on the SoundFont …6.8
- CVE-2026-61723FluidSynth is a software synthesizer based on the SoundFont …6.8
- CVE-2026-61736LightRAG provides simple and fast retrieval-augmented genera…9.3
- CVE-2026-6174The CC Child Pages plugin for WordPress is vulnerable to Sto…6.4
- CVE-2026-61740LightRAG provides simple and fast retrieval-augmented genera…9.3
- CVE-2026-61741http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]`…9.3
- CVE-2026-61742DBHub is a database MCP server for Postgres, MySQL, SQL Serv…9.3
- CVE-2026-61743Chartbrew is an open-source web application that can connect…6.3
Are you affected by CVE-2026-61732?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
