cd /news/ai-safety/how-i-found-a-high-severity-ai-secur… · home topics ai-safety article
[ARTICLE · art-79307] src=dev.to ↗ pub= topic=ai-safety verified=true sentiment=· neutral

How I Found a HIGH-Severity AI Security Issue on Khan Academy's VDP

A security researcher discovered a high-severity AI security vulnerability on Khan Academy's Vulnerability Disclosure Program (VDP). The issue involved prompt injection in an AI agent, allowing unauthorized actions. The researcher reported the flaw, and Khan Academy is addressing it.

read1 min views1 publishedJul 29, 2026
How I Found a HIGH-Severity AI Security Issue on Khan Academy's VDP
Image: Dev.to

🛠️ Tools & Resources I Use #

[Hack The Box VIP](https://amzn.to/4bHackTheBox)— practice environment for recon techniques -
[YubiKey 5C NFC](https://amzn.to/4bYubiKey)— hardware key for API token security -
[Free AI Prompt Tester](https://galeops.xyz/tools/prompt-test/)— test your own AI agent for the same bugs

As an Amazon Associate I earn from qualifying purchases.

Originally published on GaleOps Blog.

── more in #ai-safety 4 stories · sorted by recency
── more on @khan academy 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/how-i-found-a-high-s…] indexed:0 read:1min 2026-07-29 ·