hooks/useTextInput.ts:133
[AGENTS: Infiltrator - Prompt - Razor - Specter - Vector]attack_chains, attack_surface, injection, llm_security, security
**Perspective 1:** getImageFromClipboard() returns base64 image data that is directly passed to onImagePaste without validating the image format, size, or content. An attacker could paste malicious image data designed to exploit image parsing vulnerabilities or consume excessive memory.
**Perspective 2:** The getImageFromClipboard() function is called without validating the clipboard contents or the external binary it invokes. An attacker who can control clipboard contents could potentially trigger command injection or exploit vulnerabilities in the clipboard handling binary.
**Perspective 3:** The tryImagePaste function accepts base64-encoded images from clipboard without validating image content, format, or size. Malicious images could be crafted to exploit vision model vulnerabilities or contain embedded adversarial prompts in metadata/steganography.
**Perspective 4:** Ctrl+V triggers clipboard image extraction (lines 133-148) without user confirmation. Attack chain: 1) User copies sensitive screenshot (credentials, API keys, internal docs), 2) Attacker-controlled prompt tricks user into pasting, 3) Image sent to Claude API, 4) Claude extracts text via OCR, 5) Attacker retrieves via conversation history or bug report, 6) Works even if user doesn't realize they pasted an image. The IMAGE_PLACEHOLDER (line 4) provides minimal feedback.
**Perspective 5:** Pasted images are accepted and processed without validation of content type, size limits, or malicious payload screening. This could enable adversarial image inputs designed to exploit vision model vulnerabilities.
**Perspective 6:** The tryImagePaste function retrieves base64 image data from the clipboard and passes it to onImagePaste callback without validation. If this data is later processed by image libraries or sent to external services, malicious image data could exploit vulnerabilities in image parsers (e.g., ImageTragick-style attacks).
Suggested Fix
Validate clipboard data format and size before processing. Implement strict input validation on any data received from the clipboard binary. Consider sandboxing the clipboard access operation.