1.2.1
4 months ago
4 hours ago
Known vulnerabilities in the decepticon package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
decepticon is an AI-powered autonomous red team testing framework Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via Note: This is only exploitable when Decepticon is configured with a BYOK OpenAI-compatible backend whose tokenizer preserves special-token IDs (vLLM, SGLang, TGI, and Ollama are confirmed vulnerable); hosted vendors such as OpenAI and Anthropic strip these tokens server-side. How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')? Upgrade | [,1.1.17) |