This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
heySec
heysec.com
did:plc:5a3ftcqpjz27cd6rsjlfdi5j
Microsoft recorded CVE-2026-26030 and CVE-2026-25592 for prompt injection in Semantic Kernel.
Calling this "by design" confirms a clear risk: malicious text driving tool actions is a recognized threat.
https://heysec.com/2026/06/what-prompt-injection-is-and-why-microsoft-is-filing-cves/
2026-07-06T05:30:31.825Z