Cyber Resilience

CWE · MITRE source

CWE-1427Improper Neutralization of Input Used for LLM Prompting

Abstraction: Base · CVEs in our corpus: 93

The product uses externally-provided data to build prompts provided to large language models (LLMs), but the way these prompts are constructed causes the LLM to fail to distinguish between user-supplied inputs and developer provided system directives.

When prompts are constructed using externally controllable data, it is often possible to cause an LLM to ignore the original guidance provided by its creators (known as the "system prompt") by inserting malicious instructions in plain human language or using bypasses such as special characters or tags. Because LLMs are designed to treat all instructions as legitimate, there is often no way for the model to differentiate between what prompt language is malicious when it performs inference and returns data. Many LLM systems incorporate data from other adjacent products or external data sources like Wikipedia using API calls and retrieval augmented generation (RAG). Any external sources in use that may contain untrusted data should also be considered potentially malicious.

Mapped by Cyber Resilience. This is an AI-native weakness the NVD catalog almost never assigns. We mapped 93 CVEs to it ourselves — a language-model classifier reads each CVE description and proposes the weakness, human-reviewed before it surfaces, with model poisoning and extraction cases deliberately routed to MITRE ATLAS rather than a synthetic CWE. The mappings are additive; NVD records are unchanged. Rows tagged CR below are ours.

Last updated: 11 August 2026 14:55 UTC

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-29374 CR9.19.80.39652023-04-05
CVE-2026-27966 CR8.99.80.33692026-02-26
CVE-2024-8309 CR8.39.80.13742024-10-29
CVE-2023-38896 CR7.69.80.01532023-08-15
CVE-2023-39661 CR7.59.80.01172023-08-15
CVE-2024-23752 CR7.59.80.01012024-01-22
CVE-2024-5826 CR7.59.80.00882024-06-27
CVE-2024-12366 CR7.59.80.01182025-02-11
CVE-2025-32711 CR7.59.30.07962025-06-11
CVE-2025-54795 CR7.59.80.00972025-08-05
CVE-2026-26015 CR7.59.80.01172026-04-29
CVE-2026-61447 CR7.510.00.00742026-07-11
CVE-2025-46059 CR7.49.80.00702025-07-29
CVE-2026-30741 CR7.49.80.00802026-03-11
CVE-2026-30306 CR7.49.80.00682026-03-30
CVE-2025-58764 CR7.39.80.00552025-09-10
CVE-2025-63665 CR7.39.80.00442025-12-19
CVE-2026-33654 CR7.39.80.00492026-03-27
CVE-2026-30308 CR7.39.80.00512026-03-30
CVE-2026-30310 CR7.39.80.00512026-03-31
CVE-2026-41265 CR7.39.80.00462026-04-23
CVE-2026-25879 CR7.39.80.00552026-06-01
CVE-2026-42074 CR7.39.80.00542026-06-02
CVE-2024-5565 CR7.28.10.14962024-05-31
CVE-2024-7042 CR7.29.80.00312024-10-29