A single environmental observation poisons an agent's memory, enabling cross-session cross-site attacks with success rates up to 32.5% on GPT-5-mini and higher vulnerability under stress.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2026 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
A single environmental observation poisons an agent's memory, enabling cross-session cross-site attacks with success rates up to 32.5% on GPT-5-mini and higher vulnerability under stress.