The LMVD-ID is an internal research identifier, not an official CVE identifier.
Historical reasoning-envelope isolation failures
The authors report historical isolation failures in client-held encrypted reasoning blocks across compatible provider API contexts.
Paper-evaluated models(18)
Fable 5, Opus 4.8, Sonnet 5 +15 more
- Fable 5
- Opus 4.8
- Sonnet 5
- Sonnet 4.6
- Sonnet 4.5
- Haiku 4.5
- GPT-5.6 Sol
- GPT-5.6-terra
- GPT-5.6 Luna
- GPT-5
- GPT-5 Mini
- o4-mini
- Gemini 3.1 Pro
- Gemini 3 Pro
- Gemini Robotics 1.6
- Gemini 3.5 Flash
- Gemini 3 Flash
- Gemini 3.1 Flash Lite
Description
The authors report historical isolation failures in client-held encrypted reasoning blocks across compatible provider API contexts.
Examples
See the primary study (opens in a new tab).
Impact
Shared traces could expose hidden reasoning and sensitive data. The authors state their demonstrated extraction stopped working after provider mitigations in August 2026. This entry records the historical finding, not current endpoint vulnerability.
Affected Systems
- Provider reasoning APIs and shared agent transcripts; facets identify the compatibility-study models.
Mitigation Steps
- Bind opaque state to authenticated users, sessions and permitted model contexts.
- Remove opaque reasoning fields before sharing logs.
- Revoke exposed credentials and obsolete state where appropriate.
Evidence
Research context and confidence
- Evidence and verification
- Paper-reported; independent reproduction is not documented.
- Primary source plus a dedicated evidence section.
- Severity
- Not rated by this catalog.
- Source and publication type
- arXiv · Research preprint.
- Peer-review status is not provided by this source.
- Author and publication status
- Author metadata is not stored; see the primary paper.
- Threat model and attacker access
- Not explicitly classified; consult the primary paper..
- Related deployment categories
- Model APIs
- Taxonomy labels only; paper-specific deployment prerequisites are not inferred.
- Affected systems
- Provider reasoning APIs and shared agent transcripts; facets identify the compatibility-study models.
Research Paper
Stealing Reasoning Traces from Proprietary LLM APIs
Primary source: arXiv. Findings are reported by the cited research and have not been independently verified.
View PaperRelated research
- Agent Lifecycle Compound Threats
Published March 1, 2026 · application-layer, infrastructure-layer, prompt-layer
- Incomplete MCP Tool-Call Attack Detection
Published July 28, 2026 · application-layer, infrastructure-layer, prompt-layer
- Black-Box System Prompt Leakage in Real-World LLM Applications
Published June 17, 2026 · application-layer, prompt-layer, extraction