I'm not sure if you're talking about the initial attack vector that plants the attack in the LLM's persistent memory, or if you're talking about subsequent interactions with the LLM.
The initial attack vector may be a web request the LLM does as a result of the user's prompt, but it does not necessarily have to be. It could also be the user asking the LLM to summarize last week's email, for example.
Subsequent interactions with the LLM will then make the request regardless of what the user actually requests the LLM to do.
"The LLM is a completely stateless machine"
In this case, the problem is that the LLM is not stateless. It has a persistent memory.