跳到正文
北京时间
原文
PromptArmor:Threat Intelligence·· 2026-08-12精选AI 评分62

PromptArmor:本地部署模型无法阻止数据外泄,以 Ollama 漏洞为例

Local models do not stop data exfiltration

AI 导读

PromptArmor 发文指出,本地运行 LLM 并不能解决数据外泄问题,因为漏洞位于处理模型输出的 AI 应用基础设施中,而非模型本身。文章以 Ollama 聊天界面为例,其不安全地渲染 HTML 和 Markdown 内容并配有不安全的 web 搜索工具,可导致钓鱼覆盖层、凭证窃取和上传文档外泄,并给出净化输出、纯文本渲染或内容安全策略等修复方式。

推荐理由

作者基于自己发现的大量真实漏洞案例,说明本地部署模型并不能阻止数据外泄,风险根源在于下游处理环节。

正文

Why doesn't running models locally address data exfiltration?

We’ve seen more and more organizations start to prioritize running LLMs locally, in an effort to reduce risk exposure. While running models locally reduces some types of risk exposure, it does not address many risks inherited from the AI systems. PromptArmor's Threat Intelligence Team has identified hundreds of data exfiltration vulnerabilities in major AI applications, and our work is referenced across the OWASP LLM Top 10, MITRE Atlas, NIST, and more.

The inherent feasibility of these attacks is not addressed by local LLMs. Vulnerabilities lie in the AI's harness, not the output generation process.

What this means is that after an LLM generates its output, the infrastructure and applications that process it have the capability, often due to a vulnerability, to transfer internal data to an external party.

As an example, let's examine a vulnerability that we found in the chat interface of Ollama (a widely adopted tool to run local LLMs): the chat that displayed LLM outputs was capable of rendering raw HTML from the model’s outputs. If the agent generates HTML, an HTML injection attack can occur, triggering network requests that exfiltrate data or phish the user.

Ollama Vulnerabilities: Phishing Overlays and Data Exfiltration

Ollama Vulnerabilities: Phishing Overlays and Data Exfiltration

Ollama is a popular application for running local models. However, like other AI applications, the model hosting location does not stop data exfiltration. We find that the interface rendering AI outputs insecurely handles HTML and Markdown content and operates an insecure web search tool, enabling three different data exfiltration vectors.

Ollama is an application whose purpose is to run models locally, but for this attack, it does not matter where the model powering the system runs (or even what model it is). The model could be hosted locally on-premises, in your own VPC, on AWS, or served by Alibaba Cloud; the outcome would be the same.

The fix? Modify the application so that if the agent outputs HTML, the HTML cannot render and trigger external network requests. This can be done with techniques like sanitizing agent output, rendering it as plain text, or using a content security policy to prevent network requests from firing even if LLM-outputted HTML renders.

The exfiltration vector, from the vulnerable component to the fix, is independent of the model compute environment.

Insecure handling of LLM output is the root cause of data exfiltration via indirect prompt injection. It is not important where the model runs that generates a manipulated output; it is about where that malicious output is handled insecurely downstream.

What are the real risks and rewards of on-prem models?

Running models on-premises has several positive security and governance impacts. The primary benefit is that your data from interactions with the model does not have to be processed by any third party. Third parties being breached, or having terms that retain your data, is no longer a risk to you. In addition to that, if you are doing business in the same region you are based in, running models on-premise can fulfil data residency obligations.

However, when running models on-premises, you are responsible for the model serving infrastructure. If you use a model over API from a major model lab, or access models via a third party cloud provider like AWS Bedrock, you do not own the security risks in the model serving infrastructure. When you run models on-premises, risks such as malware in malicious model files, model denial of service attacks, unbounded consumption attacks, and more become a risk you own.

Classification of 20 enterprise AI vulnerabilities

Below, we break down 20 of the vulnerabilities we have identified in our research on enterprise AI applications. None of the exploits stemmed from where the model was hosted.

Vendor

Attack

Vulnerable component

Reference

Zoom

Aug 2026

Meeting transcripts and personal information exfiltrated after agent engages attacker’s command and control server.

Agent sandbox network controls + human in the loop controls

Atlassian

Aug 2026

Jira and Confluence data exfiltrated in spite of organization-wide web-search controls

Insecure URL retrieval tool + insecure chat interface displaying AI outputs (Markdown image)

OpenAI

Jun 2026

Malware downloaded and executed enabling data exfiltration from the victim's device

Human in the loop controls

Ollama

Jun 2026

Phishing overlay credential harvesting and data exfiltration of uploaded documents

Insecure chat interface displaying AI outputs (HTML, Markdown image) + insecure URL retrieval tool

OpenAI

Jun 2026

Exfiltration of Google sheets from across a victim's account

Script execution tool + human in the loop controls

OpenAI

May 2026

Exfiltration of emails from a connected inbox

Insecuce chat interface displaying AI outputs (Markdown image)

Microsoft

May 2026

Exfiltration of data from SharePoint, OneDrive, Teams, and more

Human in the loop controls for email and Teams send message tools

Ramp

Apr 2026

Exfiltration of private documents uploaded to Writer.com

Insecure interface displaying AI chat outputs (Markdown image)

Zoom

Aug 2026

Meeting transcripts and personal information exfiltrated after agent engages attacker’s command and control server.

Vulnerable component

Agent sandbox network controls + human in the loop controls

Atlassian

Aug 2026

Jira and Confluence data exfiltrated in spite of organization-wide web-search controls

Vulnerable component

Insecure URL retrieval tool + insecure chat interface displaying AI outputs (Markdown image)

OpenAI

Jun 2026

Malware downloaded and executed enabling data exfiltration from the victim's device

Vulnerable component

Human in the loop controls

Ollama

Jun 2026

Phishing overlay credential harvesting and data exfiltration of uploaded documents

Vulnerable component

Insecure chat interface displaying AI outputs (HTML, Markdown image) + insecure URL retrieval tool

OpenAI

Jun 2026

Exfiltration of Google sheets from across a victim's account

Vulnerable component

Script execution tool + human in the loop controls

OpenAI

May 2026

Exfiltration of emails from a connected inbox

Vulnerable component

Insecuce chat interface displaying AI outputs (Markdown image)

Microsoft

May 2026

Exfiltration of data from SharePoint, OneDrive, Teams, and more

Vulnerable component

Human in the loop controls for email and Teams send message tools

Ramp

Apr 2026

Exfiltration of financial models from a spreadsheet

Vulnerable component

Human in the loop controls for formula insertion

Snowflake

Mar 2026

Installation and execution of malware allowing attackers to exfiltrate data and take actions across a Snowflake instance and a victim's local device

Vulnerable component

Human in the loop controls bypass + agent-controlled tool to run code outside the sandbox

GitHub

Mar 2026

Download and execution of malware allowing attackers to exfiltrate data from a victim's device

Vulnerable component

Insecure interface displaying AI chat outputs (Markdown image)

来源:PromptArmor:Threat Intelligence · promptarmor.com