Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
MAI-2024-0040
Published:May 16, 2026
Updated:May 16, 2026
A critical vulnerability has been identified in various Large Language Models (LLMs), enabling attackers to bypass established safety and ethical protocols through a sophisticated code injection technique. This method utilizes personalized encryption and decryption functions to exploit the LLMs' code execution capabilities. By processing encrypted malicious instructions, attackers can effectively circumvent the models' security recognition mechanisms designed to prevent harmful outputs. Mitigation steps: **For AI Developers:** * Enhance LLMs' intent recognition capabilities to detect and block code resembling encryption/decryption patterns. * Implement additional safeguards to prevent the execution of arbitrary code within the model's response generation process. **For Model Trainers/Fine-tuners:** * Develop robust detection mechanisms targeting code injection via personalized encryption techniques, focusing on identifying and blocking decryption functions preceding encrypted instructions. * Improve the robustness of LLM safety mechanisms against attacks exploiting code interpretation and execution capabilities by considering diverse prompt formats and employing sophisticated methods to detect malicious intent beyond simple keyword filtering.
Related Resources (1)
Do you need more information?
Contact Us
CVSS v4
Base Score:
8.2
Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
HIGH
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
5.9
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE
AIVSS
Base Score:
5.2