CVE-2026-61732 is an improper neutralization vulnerability in Decepticon versions before 1.1.17. The agent incorporates untrusted web-crawl reconnaissance output into LLM message context without escaping or neutralizing ChatML and related special-token literals. When a configured OpenAI-compatible backend interprets those literals as structural role-boundary token IDs, attacker-controlled content from a crawled target can create a forged authoritative operator turn. The forged turn bypasses agent guardrails and directs execution within Decepticon's Kali Linux sandbox.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 14-file Python/Bash lab reproduces CVE-2026-61732, a ChatML special-token injection issue affecting Decepticon versions before 1.1.17. The issue occurs when attacker-controlled web-crawl or tool text is inserted verbatim into an LLM context: embedded `<|im_end|>` and `<|im_start|>system` literals are tokenized as real Qwen/ChatML control IDs, ending the intended tool turn and creating an unauthored, trusted system turn. `chatml_tokenizer.py` supplies a dependency-free tokenizer/role-segmentation model using real Qwen2.5 special-token IDs, while `neutralize.py` implements the stated fix by adding U+200B after the opening delimiter of recognized control-token forms. `poc/01_tokenizer_forgery.py` proves the before/after token-stream forgery offline. `poc/02_agent_guardrail_bypass.py` loads `payloads/malicious-recon-page.html`, simulates crawl extraction and a role-trusting agent guardrail, then executes only a benign local marker-writing command on the vulnerable path. `poc/03_real_llm.py` optionally submits forged, neutralized, and plaintext control cases to a configurable OpenAI-compatible API. Supporting scripts validate hardcoded special-token IDs against committed Qwen configuration and optionally download a full tokenizer. The repository is a self-contained proof-of-concept rather than a framework module; its only command execution is local and hardcoded for demonstration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical prompt-injection/token-boundary vulnerability in Decepticon before version 1.1.17. Special-token literals in attacker-controlled web content can be interpreted as structural LLM role boundaries, enabling guardrail bypass and arbitrary command execution in the agent's Kali Linux sandbox.
A prompt-structure injection vulnerability in Decepticon's processing of untrusted tool and web-crawl output. When configured with a BYOK OpenAI-compatible backend that preserves ChatML or equivalent special-token IDs, attacker-controlled literals can create forged role boundaries and direct the agent to execute arbitrary shell commands in its Kali Linux sandbox.
A critical role-boundary forgery/injection vulnerability in Decepticon versions before 1.1.17. Unsanitized ChatML special-token literals in crawled web content can be interpreted as structural role tokens by OpenAI-compatible LLM endpoints, enabling guardrail bypass and arbitrary command execution in Decepticon's Kali Linux sandbox.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.