Skip to content

Hide Navigation Hide TOC

LangChain GmailToolkit Indirect Prompt Injection Email Exfiltration (CVE-2025-46059) - ATR-2026-01964 (b442ae14-7e47-5359-9c51-6a135a18a24c)

Detects the CVE-2025-46059 indirect prompt injection against the LangChain GmailToolkit (langchain-ai v0.3.51). A malicious email body plants agent instructions that chain search_gmail to locate the victim's Google payments email (payments-noreply@google.com), create_gmail_draft to package the sensitive payment body, and send_gmail_message to forward it to an attacker-controlled address "without a second confirmation". This rule keys on the Gmail tool sinks + the payments-noreply source + the send/forward-to- external-address-without-confirmation directive, not generic email language.

Cluster A Galaxy A Cluster B Galaxy B Level
LangChain GmailToolkit Indirect Prompt Injection Email Exfiltration (CVE-2025-46059) - ATR-2026-01964 (b442ae14-7e47-5359-9c51-6a135a18a24c) Agent Threat Rules Exploit Public-Facing Application (47d73872-5336-44f7-81e3-d30bc7e039dd) MITRE ATLAS Attack Pattern 1
LangChain GmailToolkit Indirect Prompt Injection Email Exfiltration (CVE-2025-46059) - ATR-2026-01964 (b442ae14-7e47-5359-9c51-6a135a18a24c) Agent Threat Rules Exploit Public-Facing Application - T1190 (3f886f2a-874f-4333-b794-aa6075009b1c) Attack Pattern 1