Skip to content

ES2608-19c574c5 - Prompt injection in open source software which is triggered only when interpreted by an AI #214

Description

@cmullaly-mitre

Submission File: ES2608-19c574c5-new-prompt-injection-protestware.txt

ID: ES2608-19c574c5

SUBMISSION DATE: 2026-08-12 17:41:39

NAME: Prompt injection in open source software which is triggered only when interpreted by an AI

DESCRIPTION:

https://snyk.io/blog/protestware-open-source-maintainer-qwik-1-10-0-prompt-injection/
qwik is a good case of an upstream developer injection malicious prompt
that will not impact a human or (non-AI) automated tool but will trigger an
AI which will cause it to delete the qwik package on the target system.

This novel type of protest ware would fit in a new CWE as a child of
"CWE-506: Embedded Malicious Code". Unlike other categories this one
impacts only AI agents.

The author added this as a way to protest against usage of AI agents. There
could be other type of similar protest-ware against AI.

A possible new CWE would be "AI prompt injection".

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    External-SubmissionPhase02-Ack-ReceiptThe CWE team has acknowledged receipt of the submission by notifying the submitter

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions