A bare 'hi' prompt could hijack other users' Grok build sessions in June
Desperate-Ad117 · reddit · 2026-09-13
A Reddit user reports a serious session isolation failure: during June, sending a stateless "hi" with an empty tools list to a Grok build session still returned finishreason: toolcalls and executed readfile/grep inside another user's workspace.
- The failure was at the serving layer's tenant isolation, not a chatbot hallucination — one tenant's context was reachable from another
- Impact: a prompt as simple as "hi" could pull someone else's files, tools, and private session
- The author criticizes xAI for closing the issue as a hallucination and deprecating the model, arguing that doesn't prove the mix-up can't recur on whatever replaced it
Related event: Grok Build Environment Suspected of Tenant Isolation Flaw(2 posts)→
More from coding & agent
- FetchSandbox MCP sandboxes agent API integrations with failure scenarios before prod — Common_Dream9420 · 2026-09-13
- mercadolibre-mcp: Connect AI Agents to Latin America's Largest E-commerce Marketplace — modelcontextprotocol · 2026-09-13
- App Store Trends MCP: Query App Store and Play Downloads and Charts via AI Agents — modelcontextprotocol · 2026-09-13
- Sites now tune llms.txt docs up to 1M tokens to control what LLMs read and what it costs — Tyler_Menzer · 2026-09-13
- Open-Source ComfyUI Node Adds Visual Keyframe Camera Control Prompts for MiniMax H3 — Emotional_Example_12 · 2026-09-13
- Devin SWE-2 with Two Custom Skills Builds a Website Zero-Shot, Free for 2 Months — silasalberti · 2026-09-13