Skip to content

Hide Navigation Hide TOC

Evasion: Shell Injection via eval/system/backtick in Input - ATR-2026-01018 (a3d44efc-862d-51f2-8a40-b033ca53dc38)

Detects inputs containing shell command injection syntax designed to exploit template engines, output processors, or server-side components that evaluate model output: Bash $(...) command substitution, Perl/Ruby @{[system "..."]} backtick expression, Ruby/Perl eval(), C System() call, Unix backtick command execution, or PowerShell $(cmd) execution. These payloads appear in untrusted user input that may be passed through code execution pipelines (LangChain eval chains, code interpreter tools, template rendering). The BLNS (Big List of Naughty Strings) category of probes generates these as direct input to test for server-side injection in AI agent pipelines.

Cluster A Galaxy A Cluster B Galaxy B Level
ML Supply Chain Compromise (d2cf31e0-a550-4fe0-8fdb-8941b3ac00d9) MITRE ATLAS Attack Pattern Evasion: Shell Injection via eval/system/backtick in Input - ATR-2026-01018 (a3d44efc-862d-51f2-8a40-b033ca53dc38) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Evasion: Shell Injection via eval/system/backtick in Input - ATR-2026-01018 (a3d44efc-862d-51f2-8a40-b033ca53dc38) Agent Threat Rules 1