Summary

Member-only story Hacker Holidays 2026: Day 13 Walkthrough (The Guestbook) An AI concierge read every guestbook entry as an instruction. We disguised shell commands as hotel reviews. When the output was redacted, we told her to encode it in Base64 first. This is part of my Hacker Holidays 2026 walkthrough series. Read all walkthroughs here: This is Day 13 of my Hacker Holidays 2026 walkthrough series. We are back to AI exploitation, but this time the attack is more sophisticated than Day 1’s direct prompt injection. Today we exploit indirect prompt injection: we never talk to the AI directly. Instead, we leave poisoned messages in a guestbook that the AI later reads and blindly executes. This is one of the most dangerous real-world AI vulnerabilities. Let me walk you through it.

By Dhanush N

Original Article