What matters in AI.

Subscribe

Learn / AI security

Definition · AI security

Confused deputy

A confused deputy is a program tricked into using its own authority on behalf of someone who should not have it. The program carries privileges from more than one source and cannot tell which one a request comes under, so a caller with less privilege can get the program's greater authority applied to its own request.

Last reviewed

Key points

  • Norman Hardy named the problem in 1988. His example: a compiler granted write access to its own directory was tricked into overwriting the system's billing file.
  • A confused deputy holds authority from two sources at once, its operator and its caller, and cannot tell which one it is acting for.
  • It is the failure that least privilege prevents. The compiler needed one statistics file; it was granted a whole directory.
  • Capabilities fix it by bundling authority with the resource, so the deputy can only use the caller's authority; access-control lists leave the deputy's own authority open to confusion.
  • The pattern is current. NCSC calls an LLM an "inherently confusable deputy", and OWASP's excessive agency, an email assistant with send access tricked into forwarding mail, is the compiler story retold.

A confused deputy is a program that acts for two masters at once. It carries authority its operator granted it, and it is invoked by a caller who yields their own authority to it. The two authorities are meant for different jobs, but the program cannot keep them apart, so a request that should be served under the caller’s authority is served under the program’s.

How it works

Norman Hardy’s 1988 compiler is the canonical case. It collected usage statistics into a file in its own directory, so it was given home-files licence, permission to write anywhere in that directory. Any user could invoke the compiler and name a file for debug output. One user named the system billing file. The operating system checked the compiler’s privileges, not the user’s, and the compiler wrote over the billing file. The user supplied the file name; the compiler supplied the permission. Authority and designation travelled separately.

Why it matters

The confused deputy is the failure that least privilege exists to prevent. Saltzer and Schroeder’s 1975 paper states the principle plainly: “Every program and every user of the system should operate using the least set of privileges necessary to complete the job.” The compiler needed one statistics file; it was granted a whole directory, and the billing file happened to live there.

The pattern is not historical. MITRE catalogues it as CWE-441, “Unintended Proxy or Intermediary (‘Confused Deputy’)”, and classifies cross-site request forgery (CWE-352) as a weakness that requires it: the browser carries the victim’s session, and a malicious page forces it to send an authenticated request. The LLM era has revived it under a new name. The UK NCSC frames prompt injection as the exploitation of an “inherently confusable deputy”, and OWASP’s excessive agency, an email assistant granted send access when read would have done, tricked into forwarding the user’s mail, is the compiler story retold.

Where definitions disagree

Whether a confused deputy is a fixable design flaw or an inherent property of a system. On the classical reading, from Hardy and CWE-441, it is a design flaw: the deputy holds ambient authority it should not, and capabilities or least privilege eliminate the confusion. The UK NCSC’s 2025 reading extends the term to LLMs but changes its nature. An LLM is an “inherently confusable deputy”: because the model cannot separate instructions from data, the risk can be reduced but never mitigated away. The two also scope the term differently. Hardy frames it as a program carrying authority from two sources; CWE-441 frames it as a proxy that fails to preserve the origin of a request. Both describe the same failure with different emphasis, and each implies a different defence.

In practice

The same shape recurs wherever a program holds more authority than its caller needs it to hold. A compiler with a home directory of writable files. A browser that carries the user’s session cookies and cannot verify that a request came from the user. An LLM agent logged into the user’s mailbox with a tool that can send as well as read, so a crafted email can make it forward the user’s mail. In each, the deputy’s own privilege is applied to a request the deputy cannot attribute. The fix in every case is the same principle: give the program exactly the authority the job needs, and make it use the caller’s authority rather than its own.

Questions and answers

What is a confused deputy?

A confused deputy is a program that holds authority from more than one source and is tricked into using it for someone who should not have it. The classic example is Norman Hardy's 1988 compiler: given permission to write its own statistics file, it let a user overwrite the system's billing file, because the operating system granted the request using the compiler's privileges rather than the user's.

What is the difference between a confused deputy and a Trojan horse?

A Trojan horse is malicious code that runs with the privileges of the victim who launched it. A confused deputy is legitimate, trusted code that is tricked into using its own greater privileges for someone else's benefit. Both are about authority arriving with the wrong actor, but the deputy is the trusted component being conned, not malicious itself.

How does a confused deputy relate to AI agents?

An LLM agent given the user's credentials and tools with more capability than the task needs is a deputy serving two masters: the user and whoever controls its input. Prompt injection is the con. The UK NCSC calls this an "inherently confusable deputy", because the model cannot separate instructions from data, so the risk can be reduced but not removed.

How do you prevent a confused deputy?

Enforce least privilege so the program holds only the access its job needs, and in capability systems bundle authority with the resource so the deputy can only use the caller's authority. MITRE's CWE-441 also says a proxy must preserve the initiator's identity end to end. In agent systems, OWASP advises executing tools in the user's context with minimum scope and requiring approval for high-impact actions.

Sources

  1. The Confused Deputy (or why capabilities might have been invented)ACM SIGOPS Operating Systems Review, 1 Oct 1988
  2. The Protection of Information in Computer SystemsProceedings of the IEEE, 30 Sep 1975
  3. CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')MITRE
  4. CWE-352: Cross-Site Request Forgery (CSRF)MITRE
  5. Prompt injection is not SQL injectionUK National Cyber Security Centre, 8 Dec 2025
  6. LLM03:2026 Excessive AgencyOWASP GenAI Security Project, 4 Aug 2026