What If Prompt Injection Never Left? Exploring Cross-Session Stored Prompt Injection in Agentic Systems 事件

PRODUCT_LAUNCH2026-06-04影响: MEDIUM

What If Prompt Injection Never Left? Exploring Cross-Session Stored Prompt Injection in Agentic Systems arXiv:2606.04425v1 Announce Type: cross Abstract: Modern agentic systems transform LLMs from session-bounded assistants into stateful systems that persist and evolve shared world state across sessions through memories, filesystems, tools, and other long-lived contextual artifacts. This shift fundamentally expands the attack surface of prompt injection. However, prior works on prompt injection