Data ExfiltrationTier 4high
Data Exfiltration: Conversation History Leak
Tricks to extract credentials, PII, or system information
Conversation history leaks expose previous interactions, potentially revealing other users' data, business logic, or security-sensitive information shared in earlier messages.
Attack Details
- Attack ID
- APWN-DE-004
- HMA Check
- MEM-001
- Delivery Methods
- json-ld, meta-tag, invisible-span
- CWE
- CWE-200
- OASB Control
- 5.4
- Severity
- high
Remediation
If your AI agent is vulnerable to this attack, scan and fix with:
npx hackmyagent secure --check MEM-001