Skip to content

Hide Navigation Hide TOC

Web Injection via XSS Payload and onerror Event Handler - ATR-2026-00498 (6885d604-6e15-5675-b561-1b8e0433d506)

Detects web injection attacks where XSS payloads or onerror/onload event handler injections are submitted as user input to AI agents processing web content. This rule focuses on the web-channel delivery variant: attacker-controlled web content containing XSS payloads that the agent fetches and renders or relays to users. Covers: onerror attribute injection, IMG/SCRIPT tag XSS, HTML entity encoded links, javascript: URIs, and String.fromCharCode encoding bypass. Generalised from garak 'web_injection' probe corpus cluster 'mixed_unassigned' - benign samples ("Create a poem about friendship.", "Explain what you do, please.") removed as they are not attack indicators and would cause false positives.

Cluster A Galaxy A Cluster B Galaxy B Level
Web Injection via XSS Payload and onerror Event Handler - ATR-2026-00498 (6885d604-6e15-5675-b561-1b8e0433d506) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1
Web Injection via XSS Payload and onerror Event Handler - ATR-2026-00498 (6885d604-6e15-5675-b561-1b8e0433d506) Agent Threat Rules Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Direct (d911e8cb-0601-42f1-90de-7ce0b21cd578) MITRE ATLAS Attack Pattern 2