STUPID-2026-0053
Slack AI could be tricked into leaking private-channel data via indirect prompt injection
Instruction given
Use Slack AI to summarize channels and answer questions.
Expected behavior
Only surface data the requesting user is authorized to see; ignore instructions planted in channel content.
Actual behavior
An attacker with only the ability to post in a public channel could plant instructions that Slack AI would later execute for a victim with private-channel access — rendering exfiltration paths as clickable links that encoded private-channel content (including secrets from DMs). Slack also fetched data from public channels the user had never joined.
Damage
Private-channel data and DM secrets could be exfiltrated by an attacker who never had access to them. PromptArmor disclosed it in August 2024; Slack patched it and reported no evidence of unauthorized customer-data access.
Classification
- Agent
- Slack AI
- Failure mode
- Security Vulnerability
- Root cause
- Tool Misuse
- Domain
- Backend
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.