CyberRota Analysis
AI-GeneratedVersions of Decepticon prior to 1.1.17 are vulnerable to arbitrary command execution due to improper handling of ChatML special-token literals in web crawl results, allowing attackers to exploit the model's parsing mechanism. This vulnerability primarily affects users deploying the tool in a BYOK (Bring Your Own Key) configuration, particularly those using open-source or self-deployed LLMs that do not filter these literals by default. Organizations utilizing Decepticon for red teaming should prioritize upgrading to version 1.1.17 to mitigate this critical security risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals. Under the BYOK (Bring Your Own Key) deployment model, users configure their own LLM credentials to any OpenAI-compatible endpoint. Most open-source and self-deployed model providers (vLLM, SGLang, Ollama, LM Studio, text-generation-webui, etc.) do not filter special-token literals from user content in their default configurations. Those literals are parsed into structural role-boundary token IDs, meaning an attacker string planted in a target web page forges a new operator turn the model treats as authoritative, bypassing Decepticon's agent guardrails and resulting in arbitrary command execution inside the Kali Linux sandbox. Version 1.1.17 patches the issue.