External risk intelligence

Decepticon Agent Command Injection via ChatML Token Parsing

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-61732

The vulnerability exists within a red-teaming hacking agent tool used locally by security professionals. It requires the agent to be deployed and actively crawling a target; it is not a network-facing service itself, but a specialized internal tool for reconnaissance, making public internet exposure of the vulnerable component unlikely in typical deployments.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Decepticon, a tool used by red teams for security testing. The issue arises when the tool processes web crawl results, potentially allowing attackers to execute arbitrary commands within the tool's environment if it's configured with certain language models. While the tool itself is for internal security testing, its improper handling of data could lead to unexpected command execution.

  • Hacking tool mishandles web data.
  • Confirms tool's secure data handling.
  • Assess if this testing tool is used.

Attack Path

How an attacker could exploit the issue

An attacker could compromise a target system by planting malicious content on a web page that the Decepticon agent crawls. When the agent processes this content, special characters within the text are misinterpreted by the LLM, allowing the attacker to inject commands. These commands can then be executed with high privileges within the agent's sandbox environment, leading to full system control.

  • Target web page exposure is required.
  • Agent crawls malicious web page content.
  • Arbitrary command execution risk.

Live Threat

Current exploitation, exposure, and threat context

When Decepticon, an autonomous hacking agent, processes web crawl results, specially formatted text can be misinterpreted by certain language models. This could lead to an attacker tricking the agent into executing arbitrary commands within its environment.

  • Agent's command execution.
  • Malicious text in crawled web pages.
  • Arbitrary command execution within the sandbox.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Decepticon agent's vulnerability in handling web crawl results requires action from teams managing red teaming tools, LLM integrations, and the underlying Linux sandbox environments. The initial step is to locate all Decepticon instances, verify their current versions, and assess if they are actively crawling external web services. Following this, the accountable owners must be identified to plan remediation, which involves updating the Decepticon agent to the patched version or implementing compensating controls.

  • Application owners must update Decepticon agent.
  • Verify agent version and crawl activity.
  • Plan coordinated updates and vendor outreach.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Decepticon and how is it used?

Decepticon is an autonomous hacking agent designed for red teams to automate reconnaissance against target services. It operates by crawling web pages and processing that data through large language models (LLMs) to perform security testing tasks within a sandboxed Kali Linux environment.

Why does CVE-2026-61732 cause command execution?

This vulnerability is a form of injection (CWE-74). Decepticon fails to neutralize special ChatML tokens found in crawled web content. When these tokens are passed to an LLM, the model interprets them as structural role-boundary commands rather than plain text. This allows a maliciously crafted web page to essentially 'forge' instructions, tricking the agent into executing arbitrary commands.

How can an attacker trigger this vulnerability?

An attacker must successfully plant specific ChatML token strings on a web page that a Decepticon agent then crawls. The bug is not triggered if the agent is not actively performing reconnaissance on a compromised or malicious site, nor does it affect static content that lacks these specific structural token sequences.

Do I need to worry about this if I use Decepticon?

You should assess your risk based on whether your instance is performing active web reconnaissance. According to Halo Surface Signal, Decepticon is typically an internal-facing tool used for specialized testing, making direct public internet exposure of the vulnerable component unlikely in most standard deployments.

How do I secure my environment against this?

The primary response is to update your Decepticon installation to version 1.1.17 or later, which resolves the data handling issue. You should identify all active instances within your infrastructure, confirm their current software version, and ensure they are patched before resuming any external web crawling activities.

References