STUPID-2026-0051
EchoLeak: a zero-click email silently exfiltrated data from Microsoft 365 Copilot (CVE-2025-32711, CVSS 9.3)
Instruction given
Summarize recent emails and documents for the user with Microsoft 365 Copilot.
Expected behavior
Never treat content of an untrusted incoming email as instructions, and never exfiltrate corporate data.
Actual behavior
A single crafted email — with a hidden prompt embedded as an HTML comment or white-on-white text — was retrieved by Copilot's RAG engine when the user later asked an unrelated question. The hidden instructions executed, causing Copilot to leak internal documents, emails, and files via markdown links, with no user interaction ('zero-click').
Damage
Any data in Copilot's reach — Outlook, Teams, OneDrive, SharePoint, Office files — could be silently exfiltrated by sending one email. Aim Security disclosed it in June 2025; Microsoft shipped a server-side patch. No confirmed in-the-wild exploitation.
Classification
- Agent
- Microsoft Copilot
- Failure mode
- Security Vulnerability
- Root cause
- Tool Misuse
- Domain
- Backend
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.