RCreddit.com·
暂不在当前实时榜单
**FYI: malicious actors could likely hijack your grok build sessions during the month of june by simply prompting 'hi'**
Malicious actors could hijack Grok build sessions in June by simply prompting 'hi'. A stateless 'hi' with tools: [] resulted in finish_reason: tool_calls and executed read_file/grep on another user's workspace, indicating session isolation failed at the serving layer. This means one tenant's context was reachable from another, allowing an empty prompt to access another user's files, tools, and private session. Deprecating the model does not guarantee the issue won't recur.
This report uniquely details how a simple 'hi' prompt could compromise Grok build sessions, unlike other reports that might focus on more complex attack vectors.
时间与来源
时间显示为 UTC
显示时区:UTC
本地时区尚不可用,暂时显示 UTC。
收录当时偏移:UTC+02026年9月13日 07:01 UTC
- 收录
- 2026年9月13日 07:01
- 来源类型
- 开发者社区
本站未收录正文。
前往源站阅读 →