LATIDIA · Ciberseguridad
Weird Machine Compositors: Explotación de la orquestación de IA en la capa de expresión
arXiv: 2609.33413v1 Announce Type: new Abstract: Las plataformas de orquestación protegen las expresiones proporcionadas por el usuario a través de enumerar y bloquear sandboxing: reescritura AST, listas de bloqueo de propiedades de tiempo de ejecución, entornos de sandbox de plantillas.
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.33413v1 Announce Type: new Abstract: Orchestration platforms secure user-provided expressions through enumerate and block sandboxing: AST rewriting, runtime property blocklists, template sandbox environments. We demonstrate that these sandboxes are weird machines whose instruction set is the underlying language specification, and that the enumerate and block approach is unfixable, following the same trajectory that led to the deprecation of past sandboxing technologies such as Java's SecurityManager and vm2. We validate this claim through three rounds of escalating bypasses against n8n's expression sandbox (three CVEs, two CVSS 9.4, one unauthenticated), and frame these findings within a broader pattern of sandbox failures across the orchestration products category. We identify a trust laundering pattern