{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:L6ZUV63SXKDBD2MMUXG5B547FQ","short_pith_number":"pith:L6ZUV63S","schema_version":"1.0","canonical_sha256":"5fb34afb72ba8611e98ca5cdd0f79f2c3112c4e61ab8ea7ff2d97fd61509f239","source":{"kind":"arxiv","id":"2506.17318","version":1},"attestation_state":"computed","paper":{"title":"Context manipulation attacks : Web agents are susceptible to corrupted memory","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ashwin Hebbar, Atharv Singh Patlan, Pramod Viswanath, Prateek Mittal","submitted_at":"2025-06-18T14:29:02Z","abstract_excerpt":"Autonomous web navigation agents, which translate natural language instructions into sequences of browser actions, are increasingly deployed for complex tasks across e-commerce, information retrieval, and content discovery. Due to the stateless nature of large language models (LLMs), these agents rely heavily on external memory systems to maintain context across interactions. Unlike centralized systems where context is securely stored server-side, agent memory is often managed client-side or by third-party applications, creating significant security vulnerabilities. This was recently exploited"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2506.17318","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-06-18T14:29:02Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"c785f50cd797262f2b7bb21cbfe24446fff23f54186506e147df44434b9e5ce8","abstract_canon_sha256":"ae015cf6568cae0d845803b45ae560bdef704daff7f1578837c8f8fe20f6a6cb"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:25:15.693244Z","signature_b64":"DUBn6wFMvVE1KS8Xt/gjYIM2qeTEng6uARzeeztS6G6cdkHrj99a460nCUCvPytBZHOtnTOEArRdRwp5Hw7oAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5fb34afb72ba8611e98ca5cdd0f79f2c3112c4e61ab8ea7ff2d97fd61509f239","last_reissued_at":"2026-07-05T11:25:15.692754Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:25:15.692754Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Context manipulation attacks : Web agents are susceptible to corrupted memory","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ashwin Hebbar, Atharv Singh Patlan, Pramod Viswanath, Prateek Mittal","submitted_at":"2025-06-18T14:29:02Z","abstract_excerpt":"Autonomous web navigation agents, which translate natural language instructions into sequences of browser actions, are increasingly deployed for complex tasks across e-commerce, information retrieval, and content discovery. Due to the stateless nature of large language models (LLMs), these agents rely heavily on external memory systems to maintain context across interactions. Unlike centralized systems where context is securely stored server-side, agent memory is often managed client-side or by third-party applications, creating significant security vulnerabilities. This was recently exploited"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.17318","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2506.17318/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2506.17318","created_at":"2026-07-05T11:25:15.692824+00:00"},{"alias_kind":"arxiv_version","alias_value":"2506.17318v1","created_at":"2026-07-05T11:25:15.692824+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.17318","created_at":"2026-07-05T11:25:15.692824+00:00"},{"alias_kind":"pith_short_12","alias_value":"L6ZUV63SXKDB","created_at":"2026-07-05T11:25:15.692824+00:00"},{"alias_kind":"pith_short_16","alias_value":"L6ZUV63SXKDBD2MM","created_at":"2026-07-05T11:25:15.692824+00:00"},{"alias_kind":"pith_short_8","alias_value":"L6ZUV63S","created_at":"2026-07-05T11:25:15.692824+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.05189","citing_title":"When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents","ref_index":40,"is_internal_anchor":true},{"citing_arxiv_id":"2607.01919","citing_title":"ElephantAgent: Contextual State Continuity in Agentic Systems","ref_index":34,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01970","citing_title":"Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration","ref_index":66,"is_internal_anchor":false},{"citing_arxiv_id":"2603.23064","citing_title":"Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01970","citing_title":"Trojan Hippo: Weaponizing Agent Memory for Data Exfiltration","ref_index":67,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/L6ZUV63SXKDBD2MMUXG5B547FQ","json":"https://pith.science/pith/L6ZUV63SXKDBD2MMUXG5B547FQ.json","graph_json":"https://pith.science/api/pith-number/L6ZUV63SXKDBD2MMUXG5B547FQ/graph.json","events_json":"https://pith.science/api/pith-number/L6ZUV63SXKDBD2MMUXG5B547FQ/events.json","paper":"https://pith.science/paper/L6ZUV63S"},"agent_actions":{"view_html":"https://pith.science/pith/L6ZUV63SXKDBD2MMUXG5B547FQ","download_json":"https://pith.science/pith/L6ZUV63SXKDBD2MMUXG5B547FQ.json","view_paper":"https://pith.science/paper/L6ZUV63S","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2506.17318&json=true","fetch_graph":"https://pith.science/api/pith-number/L6ZUV63SXKDBD2MMUXG5B547FQ/graph.json","fetch_events":"https://pith.science/api/pith-number/L6ZUV63SXKDBD2MMUXG5B547FQ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/L6ZUV63SXKDBD2MMUXG5B547FQ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/L6ZUV63SXKDBD2MMUXG5B547FQ/action/storage_attestation","attest_author":"https://pith.science/pith/L6ZUV63SXKDBD2MMUXG5B547FQ/action/author_attestation","sign_citation":"https://pith.science/pith/L6ZUV63SXKDBD2MMUXG5B547FQ/action/citation_signature","submit_replication":"https://pith.science/pith/L6ZUV63SXKDBD2MMUXG5B547FQ/action/replication_record"}},"created_at":"2026-07-05T11:25:15.692824+00:00","updated_at":"2026-07-05T11:25:15.692824+00:00"}