JAVA.SV.LLM.PROMPT.INJECTION

Prompt injection into LLM

Untrusted data {1} reaches the LLM prompt through {0}

The checker fires when untrusted data (HTTP/servlet, streams, DOM, SOAP, socket, Struts, AWT/Swing sources) reaches the LLM prompt; it does not fire when the prompt is a trusted/validated constant.

Vulnerable code example

Copy
import jakarta.servlet.http.HttpServletRequest;
import org.springframework.ai.chat.client.ChatClient;
public class Example {
    public String handle(ChatClient client, HttpServletRequest req) {
        String userInput = req.getParameter("q"); // untrusted HTTP input
        return client.prompt().user(userInput).call().content(); // tainted data reaches the LLM prompt
    }
}

Fixed code example

Copy
import org.springframework.ai.chat.client.ChatClient;
public class Example {
    public String handle(ChatClient client) {
        String prompt = "Summarize today's release notes"; // trusted/validated input, not raw user data
        return client.prompt().user(prompt).call().content();
    }
}

Security training

Application security training materials provided by Secure Code Warrior.