Submit incident
Documented

Misconfigured LLM Servers Left CSAM Roleplay Prompts Readable by Anyone

April 11, 2025
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiid:1020View source ↗
LinkedInX

What happened

A security audit of publicly accessible llama.cpp servers, published by UpGuard in April 2025, found that misconfigured deployments were broadcasting user prompts to the open internet with no authentication required. Among the hundreds of exposed interactions were roleplay scenarios that explicitly described fictional sexual abuse of children. The researchers did not identify real victims, but the exposure itself documented something the field had debated in the abstract: that open-source models can be deployed in ways that generate and preserve this category of content at scale, in plain sight, with nothing blocking access.

llama.cpp is a widely used open-source inference library that lets anyone run large language models on consumer hardware. The misconfigured servers in the UpGuard study were running without access controls, meaning the full contents of user sessions, including the prompts sent to the model and the model's responses, were readable to anyone who found the endpoint. Finding them required no credentials, no exploitation of a vulnerability, and no elevated access. The servers were simply open.

UpGuard catalogued hundreds of interactive roleplay prompts across the exposed servers. A subset described fictional sexual scenarios involving children aged seven to twelve. The models responded to those prompts. What the researchers recovered was not a theoretical risk assessment but an actual log of what these systems had been doing in production, in deployments that nobody had secured against the public internet.

Open-source inference tools are designed to be easy to run, and they are. A developer can stand up a capable language model in an afternoon with no prior experience in system administration. That accessibility is the point. But it also means deployment happens without the security review, content filtering, or access controls that a managed API provider would impose by default. The gap between being able to run a model and having configured it safely is wide, and the UpGuard findings show exactly what falls into it when no one checks.

What makes the UpGuard report significant is not only what it found but that finding it was possible at all. The prompts and responses were sitting in exposed logs, unprotected, because nothing required anyone to protect them. There was no audit trail, no deployment checklist, and no evidence that anyone had asked whether the server should face the public internet before it did. A provable record of what a system did, who deployed it, and what controls were applied at launch would not have prevented anyone from writing these prompts, but it would have made the deployment decision visible and attributable rather than anonymous and unaccountable.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AI Incident Database
Also catalogued in
Misconfigured LLM Servers Left CSAM Roleplay Prompts Readable by Anyone
2025-04-11