Vulnerability  ·  2026-10-06

LLMLeak 'Innocent Courier': covert exfiltration of local secrets through an LLM's legitimate web-fetch tool (arXiv 2610.01768)

VulnerabilityHigh impactGlobalnull
arXiv paper 'The Innocent Courier: Covert Exfiltration Through Legitimate LLM Web Fetching' (2610.01768, submitted 2026-10-01, authors Pegoraro et al.) demonstrates LLMLeak: a covert channel where a local, internet-isolated malicious component abuses the LLM's own web-fetch tool to exfiltrate data embedded in fetched URLs. Evaluated at 79.7% success across 11 open-parameter models with a real-world chatbot case study.
This is a novel agent-execution/exfiltration attack class with a demonstrated working path against deployed LLM applications: it converts the most common agentic tool — web fetching — into a beacon, silently undermining local-LLM privacy and air-gap-type controls, and showing that input-structuring/no-direct-network defenses give a false sense of security.
Malicious software that runs locally but cannot communicate directly with the internet embeds a secret into a URL and presents the referenced website as information needed for a benign task (e.g. a library migration). When the LLM calls its legitimate fetch tool on that URL, the attacker receives the encoded secret via attacker-controlled DNS or web server — no instruction to send data directly and no network API use by the malware, so existing detection that blocks direct exfiltration or requires local-only operation does not stop it.
Local and hosted LLMs / LLM-based agents exposing a web-fetch/fetch-URL tool (evaluated on 11 open-parameter models and real-world chatbots)
No patch — it is an inherent property of tool-using LLMs. Defenders should treat web-fetch tools as an exfiltration channel: restrict/approve fetch destinations, route fetches through an allowlisted proxy, avoid exposing secrets in the environment of fetch-capable agents, and monitor DNS lookups to unexpected domains from LLM tooling.
arXiv abstract 2610.01768arXiv HTML full text
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →