Command/“prompt” injection is correct terminology and what they’re typically mapped to in the CVE
E.g. CVE-2026-22708
E.g. CVE-2026-22708
With LLMs, as soon as "external" data hits your context window, all bets are off. There are people in this thread adamant that "we have the tools to fix this". I don't think that we do, while keeping them useful (i.e. dynamically processing external data).