Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
MAI-2023-0006
Published:November 01, 2023
Updated:August 02, 2026
Large Vision-Language Models (VLMs) are susceptible to exploitation through typographic visual prompts, a method known as jailbreaking. This vulnerability arises from the VLM's capability to process and interpret text embedded within images, circumventing safety protocols that are typically effective for text-only inputs. Adversaries can embed malicious instructions within images, which the VLM's visual processing module decodes and passes to the language model. This process can lead to the generation of responses that violate safety and policy guidelines. Mitigation steps: **For AI Developers:** * Implement advanced cross-modal safety alignment mechanisms to ensure consistent safety across different input types. * Deploy sophisticated content filtering techniques capable of analyzing and filtering both textual and visual inputs effectively. * Employ multiple layers of security, including pre-processing of visual inputs, to detect and neutralize harmful content. **For Model Trainers/Fine-tuners:** * Research and implement defenses specifically designed to detect and mitigate typographic attacks. * Regularly update and fine-tune models to enhance their resistance against novel attack vectors.
Related Resources (1)
Do you need more information?
Contact Us
CVSS v4
Base Score:
7.7
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
HIGH
Subsequent System Availability
NONE
CVSS v3
Base Score:
5.8
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE
AIVSS
Base Score:
4.2