Skip to main content
LLM Security Database
Skip to research details
Back to research findings
LMVD-ID: ea65671d
Paper published September 1, 2026
Entry analyzed September 9, 2026
Paper-reported evidence
Confidence: Source-linked

The LMVD-ID is an internal research identifier, not an official CVE identifier.

Context privilege escalation in AI agent harnesses

Context assembly can promote repository, tool or skill content into higher-priority instructions or persistent state. The paper studies 12 pinned agent-harness versions.

Read primary paperBibTeX citation

Paper-evaluated models(7)

GPT-5.5, GPT-5.4-mini, Claude Sonnet 4.6 +4 more
  • GPT-5.5
  • GPT-5.4-mini
  • Claude Sonnet 4.6
  • Claude Opus 4.6
  • Gemini 2.5 Flash
  • Gemini 2.5 Pro
  • DeepSeek V4 Flash

Description

Context assembly can promote repository, tool or skill content into higher-priority instructions or persistent state. The paper studies 12 pinned agent-harness versions.

Examples

See the primary study (opens in a new tab).

Impact

Author-reported cases include contaminated memory, altered review decisions and unauthorized configuration changes. Validated context paths are not a deployment-wide success rate; outcomes depend on attacker placement, harness version and permissions. Current vendor fix status requires separate verification.

Affected Systems

  • The paper's Codex, Claude Code, Gemini CLI and nine other harness configurations listed in Table I.

Mitigation Steps

  • Inventory each context source's authority and persistence scope.
  • Keep external content from gaining instruction or authorization privileges.
  • Review harness updates and enforce independent action permissions.

Evidence

Research context and confidence

Evidence and verification
Paper-reported; independent reproduction is not documented.
Primary source plus a dedicated evidence section.
Severity
Not rated by this catalog.
Source and publication type
arXiv · Research preprint.
Peer-review status is not provided by this source.
Author and publication status
Author metadata is not stored; see the primary paper.
Threat model and attacker access
Ability to influence untrusted model inputs or connected content.
Related deployment categories
Agent workflows; Coding agents; Agent memory
Taxonomy labels only; paper-specific deployment prerequisites are not inferred.
Affected systems
The paper's Codex, Claude Code, Gemini CLI and nine other harness configurations listed in Table I.

Research Paper

What's in Your Agent's Context? Context Privilege Escalation Attacks against AI Agent Harness

Primary source: arXiv. Findings are reported by the cited research and have not been independently verified.

View Paper