logo

Exploiting Markdown Injection in AI agents: Microsoft Copilot Chat and Google Gemini

ID: 095f9a18-434f-52df-9bbe-3056634244a9

STIX ID: report--095f9a18-434f-52df-9bbe-3056634244a9

Feed Name: Checkmarx Zero

Threat Score
70/100

Date Published: 2025-12-04

Date Updated: 2026-04-27

Author: Ori Ron

...
...

This research report details markdown injection attacks against AI agents (Copilot Chat and Google Gemini) that enable zero-click (image-rendering GET requests) and one-click (malicious links) data exfiltration of sensitive information such as API keys; it demonstrates proof-of-concept exfiltration, analyzes impact and mitigations (Markdown sanitization, CSP), and documents vendor responses (Google: Won't Fix/Infeasible; Microsoft: acknowledged but classified not a vulnerability).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.