AI Security#136Your Planner Is the Single Point of Failure
GPT-5 achieved an attack success rate of 0.68 against planning-phase prompt injection. That is the finding from PlanFlip, a paper published on arXiv (2607.16199). The strongest model was the most vulnerable.









































































































































