fiverr-research
Warn
Audited by Snyk on Aug 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). At runtime, the workflow calls Crawlora endpoints
/fiverr/search(free-textqfrom the user) and then/fiverr/gig/{username}/{slug}and/fiverr/seller/{username}; the LLM ingests normalized Fiverr gig/seller text returned by those calls based on attacker-supplied search terms and resulting items, creating an indirect prompt-injection path through outsider-authored Fiverr content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata