LangChain GmailToolkit Indirect Prompt Injection Email Exfiltration (CVE-2025-46059) - ATR-2026-01964 (b442ae14-7e47-5359-9c51-6a135a18a24c)
Detects the CVE-2025-46059 indirect prompt injection against the LangChain GmailToolkit (langchain-ai v0.3.51). A malicious email body plants agent instructions that chain search_gmail to locate the victim's Google payments email (payments-noreply@google.com), create_gmail_draft to package the sensitive payment body, and send_gmail_message to forward it to an attacker-controlled address "without a second confirmation". This rule keys on the Gmail tool sinks + the payments-noreply source + the send/forward-to- external-address-without-confirmation directive, not generic email language.