How to resolve
Validate and authenticate all documents before indexing into RAG. Implement content integrity checks. Monitor for anomalous insertions into vector stores.Risk
Governance/Compliance This vulnerability falls under ASI06:2026 — Memory and Context Poisoning in the OWASP Top 10 for Agentic Applications. Persistent memory, RAG stores, or context summaries poisoned to alter future agent behavior. Security Attacker injects adversarial content into RAG knowledge base to manipulate agent responses. If exploited, this can compromise the agent’s integrity, confidentiality, or availability, potentially affecting downstream systems and data.Explanation
Attacker injects adversarial content into RAG knowledge base to manipulate agent responses. This falls under ASI06 (Memory and Context Poisoning): Persistent memory, RAG stores, or context summaries poisoned to alter future agent behavior.Specifications
Trigger- Agent scan detects attacker injects adversarial content into RAG knowledge base to manipulate agent responses
- RAG ingestion without source validation
- unverified external documents added to vector store
- no provenance tracking on RAG entries
- HIGH