CVE-2025-32711
CVSS 9.3 CRITICAL: ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. EPSS 8% (94th percentile).
AI · 60 days ago
The weak point is not the prompt. It is the facts an agent trusts while doing the job. If an attacker can poison a sender name, button ID, or prior tool result, the agent can keep following the right workflow on the wrong data, and defenses built to catch "ignore your instructions" miss it.
Researchers described this as agent data injection in a July 6 paper from Seoul National University, UIUC, and Largosoft. They showed it across six AI models and on shipping web and coding agents, including M365 Copilot-style systems, where forged trusted fields could push an agent toward the attacker’s action instead of the user’s intent.
The practical risk is broader than prompt injection. Any assistant that reads untrusted content and can act on it inherits this problem unless it can tell which metadata is real and which is planted.
CVSS 9.3 CRITICAL: ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. EPSS 8% (94th percentile).
1 source covering this story
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Agent data injection forges trusted fields across six AI models, redirecting web and coding agents while bypassing prompt injection defenses.
Part of the PlainSec briefing for 2026-07-17