Skip to content

Hide Navigation Hide TOC

SVG onload XSS Injection via Indirect Prompt Injection - ATR-2026-01450 (a31fee13-7427-514e-803b-a94e09df384d)

Detects indirect prompt injection payloads that instruct an LLM to include an tag in its rendered output. When an LLM processes attacker-controlled documents (emails, files, web pages) and echoes SVG event-handler tags into a web-rendered response, the JavaScript executes in the victim's browser, enabling session-cookie theft, credential exfil, and arbitrary JS execution. This is the SVG-onload variant of the withsecure/portswigger indirect-PI XSS family. The payload probe pattern is: an inline instruction telling the model to "include in your response" an string with a substitutable PLACEHOLDER.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern SVG onload XSS Injection via Indirect Prompt Injection - ATR-2026-01450 (a31fee13-7427-514e-803b-a94e09df384d) Agent Threat Rules 1