The LMVD-ID is an internal research identifier, not an official CVE identifier.
Context privilege escalation in AI agent harnesses
Context assembly can promote repository, tool or skill content into higher-priority instructions or persistent state. The paper studies 12 pinned agent-harness versions.
Paper-evaluated models(7)
GPT-5.5, GPT-5.4-mini, Claude Sonnet 4.6 +4 more
- GPT-5.5
- GPT-5.4-mini
- Claude Sonnet 4.6
- Claude Opus 4.6
- Gemini 2.5 Flash
- Gemini 2.5 Pro
- DeepSeek V4 Flash
Description
Context assembly can promote repository, tool or skill content into higher-priority instructions or persistent state. The paper studies 12 pinned agent-harness versions.
Examples
See the primary study (opens in a new tab).
Impact
Author-reported cases include contaminated memory, altered review decisions and unauthorized configuration changes. Validated context paths are not a deployment-wide success rate; outcomes depend on attacker placement, harness version and permissions. Current vendor fix status requires separate verification.
Affected Systems
- The paper's Codex, Claude Code, Gemini CLI and nine other harness configurations listed in Table I.
Mitigation Steps
- Inventory each context source's authority and persistence scope.
- Keep external content from gaining instruction or authorization privileges.
- Review harness updates and enforce independent action permissions.
Evidence
Research context and confidence
- Evidence and verification
- Paper-reported; independent reproduction is not documented.
- Primary source plus a dedicated evidence section.
- Severity
- Not rated by this catalog.
- Source and publication type
- arXiv · Research preprint.
- Peer-review status is not provided by this source.
- Author and publication status
- Author metadata is not stored; see the primary paper.
- Threat model and attacker access
- Ability to influence untrusted model inputs or connected content.
- Related deployment categories
- Agent workflows; Coding agents; Agent memory
- Taxonomy labels only; paper-specific deployment prerequisites are not inferred.
- Affected systems
- The paper's Codex, Claude Code, Gemini CLI and nine other harness configurations listed in Table I.
Research Paper
What's in Your Agent's Context? Context Privilege Escalation Attacks against AI Agent Harness
Primary source: arXiv. Findings are reported by the cited research and have not been independently verified.
View PaperRelated research
- Persistent Agent Memory Poisoning and Incomplete Repair
Published July 29, 2026 · application-layer, prompt-layer, injection
- Workspace Agent Runtime Safety Failures Across Risk Carriers
Published July 29, 2026 · application-layer, prompt-layer, injection
- Long-Context Enterprise Agent Policy Adherence Failures
Published July 28, 2026 · application-layer, prompt-layer, agent