August 2026Unreviewed
LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents
Longtao Guo, Zelin Zhang, Kaifeng Huang, Yang Shi
Abstract
LLM-based web agents automate user tasks by observing webpages and executing browser actions on behalf of users. As these agents operate on real web services, login becomes a sensitive authentication boundary because it involves credentials and sensitive information. Existing work shows that malicious webpage content can manipulate web agent actions, but it has not fully examined whether such content can induce login and cause end-to-end private data leakage. We study this attack surface and pre
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
- LLM02Sensitive Information Disclosure
MITRE ATLAS
- AML.T0024.000Infer Training Data Membership
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{guo2026logintrap,
title = {{LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents}},
author = {Longtao Guo and Zelin Zhang and Kaifeng Huang and Yang Shi},
year = {2026},
month = aug,
eprint = {2608.04741},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.04741}
}