Skip to content
Search
paperAugust 2026Unreviewed

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents

Longtao Guo, Zelin Zhang, Kaifeng Huang, Yang Shi

Abstract

LLM-based web agents automate user tasks by observing webpages and executing browser actions on behalf of users. As these agents operate on real web services, login becomes a sensitive authentication boundary because it involves credentials and sensitive information. Existing work shows that malicious webpage content can manipulate web agent actions, but it has not fully examined whether such content can induce login and cause end-to-end private data leakage. We study this attack surface and pre

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM01Prompt Injection
  • LLM02Sensitive Information Disclosure
MITRE ATLAS
  • AML.T0024.000Infer Training Data Membership
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{guo2026logintrap,
  title = {{LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents}},
  author = {Longtao Guo and Zelin Zhang and Kaifeng Huang and Yang Shi},
  year = {2026},
  month = aug,
  eprint = {2608.04741},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.04741}
}