[ 
https://issues.apache.org/jira/browse/CAMEL-24607?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Work on CAMEL-24607 started by Andrea Cosentino.
------------------------------------------------
> camel-langchain4j-agent-api: CodeInjectionGuardrail blocks legitimate input 
> by counting duplicate same-type matches
> -------------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24607
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24607
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-langchain4j-agent
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> CodeInjectionGuardrail.validate() (around lines 221-246) collects matched 
> injection patterns into a List<InjectionType> without de-duplication, then in 
> non-strict mode blocks the input when detected.size() >= 2. The inline 
> comment states the intent is to require multiple DIFFERENT types, but because 
> several patterns share the same InjectionType (4 SHELL_COMMAND, 4 
> SQL_INJECTION, 3 JAVASCRIPT, 2 HTML_XSS, 2 TEMPLATE_INJECTION), a single 
> input matching two patterns of ONE type is blocked.
> Concretely, a normal templating question such as "how do I use {{name}} and 
> ${value} in my template?" matches both TEMPLATE_INJECTION patterns and is 
> rejected as a false positive (the message even prints the duplicated list, 
> e.g. [TEMPLATE_INJECTION, TEMPLATE_INJECTION]). This is reachable via the 
> default CodeInjectionGuardrail and Guardrails.strictInputGuardrails().
> The sibling PromptInjectionGuardrail de-duplicates correctly. Fix: only add a 
> type when not already present (if (!detected.contains(pattern.getType()))).
> _Reported by an automated functional audit._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to