Is Prompt Injection a Vulnerability?

184 · Daniel Miessler · Nov. 26, 2025, 2:01 a.m.
Summary
The author argues that prompt injection should be classified as a vulnerability due to its technical implications and the overall risk it presents to systems. Using analogies such as the Pope’s vulnerability in crowds and comparing it to SQL injection, the post emphasizes the need for creative thinking to address these vulnerabilities rather than dismissing them as inherent risks.