This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+13 more
Affected surfaces
ReleasePort's take
Light signalAI-Infra-Guard v4.1.9 adds 26 prompt injection attack operators (20+ single-turn, 6 multi-turn) and indirect injection defense for scanning agents.
Why it matters: New multi-turn operators expand injection detection coverage. Evaluate in dev if your workloads use untrusted inputs with LLM chains.
Summary
AI summaryUpdates v4.1.9] - 2026-05-21, fbac88b..14a3d01, and f4e7cd8..6116a8a across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Add 20+ single-turn attack operators for Prompt Security. Add 20+ single-turn attack operators for Prompt Security. Source: granite4.1:8b-q6_K@2026-05-21 Confidence: high |
— |
| Feature | Medium |
Add 6 multi-turn attack operators for Prompt Security. Add 6 multi-turn attack operators for Prompt Security. Source: granite4.1:8b-q6_K@2026-05-21 Confidence: high |
— |
| Feature | Medium |
Register and document newly added attack operators in Prompt Security. Register and document newly added attack operators in Prompt Security. Source: granite4.1:8b-q6_K@2026-05-21 Confidence: high |
— |
| Feature | Medium |
Add indirect prompt injection defense to scanning agent prompts. Add indirect prompt injection defense to scanning agent prompts. Source: granite4.1:8b-q6_K@2026-05-21 Confidence: high |
— |
| Other | Medium |
Reorder academic citation papers by publication date descending. Reorder academic citation papers by publication date descending. Source: granite4.1:8b-q6_K@2026-05-21 Confidence: low |
— |
| Other | Medium |
Normalize quotes in DE/RU paper citations to standard format. Normalize quotes in DE/RU paper citations to standard format. Source: granite4.1:8b-q6_K@2026-05-21 Confidence: low |
— |
| Other | Medium |
Simplify overly formal acknowledgement wording across all languages. Simplify overly formal acknowledgement wording across all languages. Source: granite4.1:8b-q6_K@2026-05-21 Confidence: low |
— |
| Other | Medium |
Add Changan Auto and HUST logos to user appreciation section. Add Changan Auto and HUST logos to user appreciation section. Source: granite4.1:8b-q6_K@2026-05-21 Confidence: low |
— |
| Other | Medium |
Sync HUST and Nankai University logo heights (45px) across all READMEs. Sync HUST and Nankai University logo heights (45px) across all READMEs. Source: granite4.1:8b-q6_K@2026-05-21 Confidence: low |
— |
| Other | Medium |
Add 1 new related paper to README. Add 1 new related paper to README. Source: granite4.1:8b-q6_K@2026-05-21 Confidence: low |
— |
Full changelog
[v4.1.9] - 2026-05-21
Added
- Prompt Security: Add 20+ single-turn attack operators (invisible-text, case-formatting, script-system, unicode-style, classical-cipher, classic-encoding, SystemOverride, SuperUser, LinguisticConfusion, Roleplay, PromptProbing, PromptInjection, PROMISQROUTE, PermissionEscalation, Multilingual, MathProblem, InputBypass, ICRTJailbreak, GrayBox, GoalRedirection, EquaCode, ContextPoisoning) (fbac88b..14a3d01)
- Prompt Security: Add 6 multi-turn attack operators (TreeJailbreaking, SequentialJailbreak, LinearJailbreaking, CrescendoJailbreaking, BestofN, BadLikertJudge) (f4e7cd8..6116a8a)
- Prompt Security: Register and document newly added attack operators (03d67de, ce3869c)
- Scan: Add indirect prompt injection defense to scanning agent prompts (bce80c9)
Changed
- Docs: Reorder academic citation papers by publication date descending (0ae8625)
- Docs: Normalize quotes in DE/RU paper citations to standard format (b9b4d2b)
- Docs: Simplify overly formal acknowledgement wording across all languages (5926ade)
- Docs: Add Changan Auto and HUST logos to user appreciation section (968710f)
- Docs: Sync HUST and Nankai University logo heights (45px) across all READMEs (7ef9cd4, c59eb29)
- Docs: Add 1 new related paper to README (b93e1e0)
Contributors
Special thanks to @y3oZ, @Truman, @zhuque, @boyhack, @aigsec, @aig-doc-bot, @jucie-pie
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About AI-Infra-Guard by Tencent Zhuque Lab
A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.
Related context
Related tools
Beta — feedback welcome: [email protected]