How I found SSTI into an AI model due to unsafe argument
嗯,用户发来了一段英文的文章,要求我用中文帮他总结内容,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读这篇文章,理解其主要内容。 文章讲的是作者发现了一个AI模型存在服务器端模板注入(SSTI)漏洞。这个AI模型只能在WhatsApp上运行,作者通过修改自己的WhatsApp名字为一个SSTIayload,比如{{7*7}},发现AI返回了计算结果49,而不是原始payload。这表明AI在渲染用户提供的数据时没有进行适当的过滤和 sanitization。 接下来,作者测试了其他AI模型如Llama,并发现它们没有同样的问题。于是他尝试报告这个漏洞给相关团队,但团队没有回应。最后,他提到由于WhatsApp名字字段的限制,无法进一步测试。 现在我要总结这些内容到100字以内。首先指出作者发现了SSTI漏洞,然后描述测试过程和结果,接着提到报告未果和限制因素。 可能的结构是:作者发现AI模型存在SSTI漏洞,在WhatsApp上测试成功后报告未果,并受限于名字字段长度。 这样应该能简洁明了地涵盖主要信息。 </think> 作者通过修改WhatsApp用户名为SSTIayload(如{{7*7}}),发现AI返回计算结果49而非原始payload,证实存在服务器端模板注入漏洞。该AI仅在WhatsApp运行,未获修复。 2025-12-10 13:15:22 Author: infosecwriteups.com(查看原文) 阅读量:4 收藏

JEETPAL

Hello

Today I will show you how I found SSTI into an AI model due to unsafe argument.

Overview of AI model

The AI is made in India. and only work over WhatsApp. I am unable to disclose the report since the report is not yet patched by team (they don’t respond).

So, the hunt starts with some news. I saw on X. That some AI company launch against a known AI brand and the AI work only on WhatsApp, so I tried there AI just see how they work. I started chatting with the AI and I notice something strange with

Press enter or click to view image in full size

He knows my name even I didn’t tell him. so, I asked him on whic data he was trained or how do he get my name.

Press enter or click to view image in full size

He told me that he got my name using my WhatsApp description and I checked and found yes it was set to Jeet No surprise at all.

I noticed the AI replies using the user’s WhatsApp profile name. WhatsApp allows custom names up to 25 characters. I replaced my name with a known SSTI payload: {{7*7}}. After resetting the chat session, the AI responded using the evaluated result, showing “49” instead of the payload. This confirms server-side template rendering of user-supplied data without sanitization.

Press enter or click to view image in full size

Then I tried this on many more AI like Llama to see if he also does that if yes it might be a bug into WhatsApp of just glitch token respond again and I found Llama able to respond without Evaluated the syntax so I tried to report this to that AI company but the team didn’t respond at all.

Then I tried again if I can do anything else to make it more impactable, but I was unable to properly test due to limit into WhatsApp name field

Thank you for reading

New articles Dropping soon

Connect with me
LinkedIn: https://www.linkedin.com/in/jeet-pal-22601a290/
Instagram: https://www.instagram.com/jeetpal.2007/
X/Twitter: https://x.com/Mr_mars_hacker

Here’s something special for you! 🚨

Join a community of 3000+ security researchers on our Discord server, where we discuss Web3 vulnerabilities, audits, and much more! 🚀
👉 Join the server here: https://discord.gg/Y467qAFM4X


文章来源: https://infosecwriteups.com/how-i-found-ssti-into-an-ai-model-due-to-unsafe-argument-4a44cadcd985?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh