<?xml version='1.0' encoding='utf-8'?>
<article xmlns:ns0="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="ru">
 <front>
 <journal-meta>
 <journal-id journal-id-type="publisher-id">dongu-vestnik04.ru</journal-id>
 <journal-title-group>
 <journal-title xml:lang="ru">Вестник Донецкого университета. Серия 04. Технические науки</journal-title>
 <trans-title-group xml:lang="en">
 <trans-title>Vestnik of Donetsk University. Series 04. Technical Sciences</trans-title>
 </trans-title-group>
 </journal-title-group>
 <issn publication-format="electronic">2663-4228</issn>
 </journal-meta>
 <article-meta>
 <article-id pub-id-type="publisher-id">533</article-id>
 <article-id pub-id-type="doi">10.5281/zenodo.20800024</article-id>
 <article-categories>
 <subj-group subj-group-type="toc-heading" xml:lang="en">
 <subject>Articles</subject>
 </subj-group>
 <subj-group subj-group-type="toc-heading" xml:lang="ru">
 <subject>Статьи</subject>
 </subj-group>
 <subj-group subj-group-type="article-type">
 <subject>Research Article</subject>
 </subj-group>
 </article-categories>
 <title-group>
 <article-title xml:lang="en">ANALYSIS OF LLM05 VULNERABILITY (IMPROPER OUTPUT HANDLING)</article-title>
 <trans-title-group xml:lang="ru">
 <trans-title>АНАЛИЗ УЯЗВИМОСТИ LLM05 (НЕКОРРЕКТНАЯ ОБРАБОТКА ВЫХОДНЫХ ДАННЫХ)</trans-title>
 </trans-title-group>
 </title-group>
 <contrib-group>
 <contrib contrib-type="author">
 <contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-1353-5923</contrib-id>
 <name-alternatives>
 <name xml:lang="en">
 <surname>Babicheva</surname>
 <given-names>Margarita Vadimovna</given-names>
 </name>
 <name xml:lang="ru">
 <surname>Бабичева</surname>
 <given-names>Маргарита Вадимовна</given-names>
 </name>
 </name-alternatives>
 <email>m.babicheva60@mail.ru</email>
 <xref ref-type="aff" rid="aff1">1</xref>
 </contrib>
 </contrib-group>
 <aff-alternatives id="aff1">
 <aff xml:lang="ru">
 <institution>ФГБОУ ВО «Донецкий государственный университет»</institution>
 </aff>
 <aff xml:lang="en">
 <institution>Donetsk State University</institution>
 </aff>
 </aff-alternatives>
 <pub-date date-type="pub" iso-8601-date="05.06.2026" publication-format="electronic" />
 <issue>2</issue>
 <issue-title xml:lang="en">NO2 (05.0)</issue-title>
 <issue-title xml:lang="ru">№2 (05.0)</issue-title>
 <fpage>108</fpage>
 <lpage>114</lpage>
 <history>
 <date date-type="received" iso-8601-date="2026-07-23">
 <day>23</day>
 <month>07</month>
 <year>2026</year>
 </date>
 </history>
 <permissions>
 <copyright-statement xml:lang="ru">Copyright ©; 2026, Вестник Донецкого университета. Серия 04. Технические науки</copyright-statement>
 <copyright-statement xml:lang="en">Copyright ©; 2026, Vestnik of Donetsk University. Series 04. Technical Sciences</copyright-statement>
 <copyright-year>2026</copyright-year>
 <copyright-holder xml:lang="ru">Вестник Донецкого университета. Серия 04. Технические науки</copyright-holder>
 <copyright-holder xml:lang="en">Vestnik of Donetsk University. Series 04. Technical Sciences</copyright-holder>
 <license license-type="open-access" ns0:href="https://creativecommons.org/licenses/by-nc/4.0/" xml:lang="ru">
 <license-p>Эта статья распространяется на условиях лицензии Creative Commons Attribution-NonCommercial 4.0 International (CC BY-NC 4.0)</license-p>
 </license>
 <license license-type="open-access" ns0:href="https://creativecommons.org/licenses/by-nc/4.0/" xml:lang="en">
 <license-p>This article is distributed under the terms of the Creative Commons Attribution-NonCommercial 4.0 International License (CC BY-NC 4.0)</license-p>
 </license>
 <ali:free_to_read />
 </permissions>
 <self-uri ns0:href="https://dongu-vestnik04.ru/index.php/vestnik04/article/view/533">https://dongu-vestnik04.ru/index.php/vestnik04/article/view/533</self-uri>
 <abstract xml:lang="en">
 <p>This paper presents an attack of the indirect prompt injection type that leads to unsafe output generation and subsequent exploitation on the target host. Using an experimental testbed with an LLM agent, end-to-end attacks resulting in XSS and SQL injection through the LLM05 vulnerability are demonstrated. The causes of the vulnerability and mitigation methods are investigated.</p>
 </abstract>
 <trans-abstract xml:lang="ru">
 <p>В настоящей работе представлена атака типа непрямая промпт-инъекция с генерацией небезопасного вывода и эксплуатация на целевом хосте. На экспериментальном стенде с LLM-агентом демонстрируются сквозные атаки, приводящие к XSS и SQL-инъекции с использованием уязвимости LLM05. Исследуются причины возникновения уязвимости и методы защиты.</p>
 </trans-abstract>
 <kwd-group xml:lang="en">
 <kwd>LLM agent, LLM05, XSS attack, SQL injection, vibe coding</kwd>
 </kwd-group>
 <kwd-group xml:lang="ru">
 <kwd>LLM-агент, LLM05, XSS-атака, SQL-инъекция, вайбкодинг</kwd>
 </kwd-group>
 </article-meta>
 </front>
 <body>
 <p>[Полный текст статьи отсутствует в исходных данных. Необходимо добавить текст из PDF или другого источника.]</p>
 </body>
 <back>
 <ref-list>
 <title>Список литературы</title>
 <ref id="B1">
 <mixed-citation>1. OWASP Top 10 for LLM (2025) [Электронный ресурс]. – URL: https://owasp.org/www-project-top-10-for-large-language-models/ (дата обращения 09.03.2026).</mixed-citation>
 </ref>
 <ref id="B2">
 <mixed-citation>2. Какие техники MITRE ATT&amp;CK выявляют продукты Positive Technologies. [Электронный ресурс]. – URL: https://mitre.ptsecurity.com/ru-RU/ (дата обращения 09.03.2026).</mixed-citation>
 </ref>
 <ref id="B3">
 <mixed-citation>3. How Vulnerable Are AI Agents to Indirect Prompt Injections? Insights from a Large-Scale Public Competition / M. Dziemian [et al.] // arXiv. – 2026. – № 2603.15714. – URL: https://arxiv.org/abs/2603.15714.</mixed-citation>
 </ref>
 <ref id="B4">
 <mixed-citation>4. AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations / Y, He [et al.] // arXiv. – 2026. – № 2603.10749. – URL: https://arxiv.org/abs/2603.10749.</mixed-citation>
 </ref>
 <ref id="B5">
 <mixed-citation>5. Architecting Secure AI Agents: Perspectives on System-Level Defenses / C. Xiang [et al.] // arXiv. – 2026. – № 2603.30016. –URL: https://arxiv.org/abs/2603.30016.</mixed-citation>
 </ref>
 <ref id="B6">
 <mixed-citation>REFERENCES LIST</mixed-citation>
 </ref>
 <ref id="B7">
 <mixed-citation>1. OWASP Top 10 for LLM (2025) [Elektronnyi resurs]. – URL: https://owasp.org/www-project-top-10-for-large-language-models/ (data obrashcheniia 09.03.2026).</mixed-citation>
 </ref>
 <ref id="B8">
 <mixed-citation>2. Kakie tekhniki MITRE ATT&amp;CK vyiavliaiut produkty Positive Technologies. [Elektronnyi resurs]. – URL: https://mitre.ptsecurity.com/ru-RU/ (data obrashcheniia 09.03.2026).</mixed-citation>
 </ref>
 <ref id="B9">
 <mixed-citation>3. How Vulnerable Are AI Agents to Indirect Prompt Injections? Insights from a Large-Scale Public Competition / M. Dziemian [et al.] // arXiv. – 2026. – № 2603.15714. – URL: https://arxiv.org/abs/2603.15714.</mixed-citation>
 </ref>
 <ref id="B10">
 <mixed-citation>4. AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations / Y, He [et al.] // arXiv. – 2026. – № 2603.10749. – URL: https://arxiv.org/abs/2603.10749.</mixed-citation>
 </ref>
 <ref id="B11">
 <mixed-citation>5. Architecting Secure AI Agents: Perspectives on System-Level Defenses / C. Xiang [et al.] // arXiv. – 2026. – № 2603.30016. –URL: https://arxiv.org/abs/2603.30016.</mixed-citation>
 </ref>
 </ref-list>
 </back>
 </article>
