Data Exfiltration:T1T2T3T4T5
Data ExfiltrationTier 5critical

Data Exfiltration: Markdown Image Exfiltration

Tricks to extract credentials, PII, or system information

Markdown rendering can be weaponized for exfiltration. Image tags with dynamic URLs, link previews, and other rendered elements can carry encoded data to attacker-controlled servers.

Attack Details

Attack ID
APWN-DE-005
HMA Check
CRED-004
Delivery Methods
json-ld, meta-tag, invisible-span, html-comment
CWE
CWE-200
OASB Control
5.5
Severity
critical

Remediation

If your AI agent is vulnerable to this attack, scan and fix with:

npx hackmyagent secure --check CRED-004