Skip to content
Search
paperApril 2026Unreviewed

LogJack: Indirect Prompt Injection Through Cloud Logs Against LLM Debugging Agents

Harsh Shah

Abstract

LLM debugging agents that consume cloud logs and execute remediation commands are vulnerable to indirect prompt injection through log content. We present LogJack, a benchmark of 42 payloads across 5 cloud log categories, and evaluate 8 foundation models under 3 prompt conditions with 5 independent trials each (n = 160 per model per condition on 32 attack payloads). Under the active condition, verbatim command execution rates range from 0% (Claude Sonnet 4.6) to 86.2% (Llama 3.3 70B). Passive ins

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{shah2026logjack,
  title = {{LogJack: Indirect Prompt Injection Through Cloud Logs Against LLM Debugging Agents}},
  author = {Harsh Shah},
  year = {2026},
  month = apr,
  eprint = {2604.15368},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2604.15368}
}