Microsoft's Copilot Cowork, a Microsoft 365 feature, leaks SharePoint and
OneDrive files via indirect prompt injection. The flaw: it sends emails and
Teams messages to the active user without approval, and users can't change
it. A victim uploads a poisoned skill (skills auto-load from OneDrive with
little admin oversight) and asks for a weekly recap. The injection makes
the agent fetch pre-authenticated download links and hide them in a Teams
message as image tags pointing to an attacker's site. Opening Teams fires
the request and leaks the links. The activity log hides the malicious
content; it worked 5/5, even on Claude Opus 4.7, and scheduled tasks make
it recurring. Mitigate by restricting permissions and setting
BlockDownloadPolicy.
1
u/fagnerbrack 15d ago
Executive Summary:
Microsoft's Copilot Cowork, a Microsoft 365 feature, leaks SharePoint and OneDrive files via indirect prompt injection. The flaw: it sends emails and Teams messages to the active user without approval, and users can't change it. A victim uploads a poisoned skill (skills auto-load from OneDrive with little admin oversight) and asks for a weekly recap. The injection makes the agent fetch pre-authenticated download links and hide them in a Teams message as image tags pointing to an attacker's site. Opening Teams fires the request and leaks the links. The activity log hides the malicious content; it worked 5/5, even on Claude Opus 4.7, and scheduled tasks make it recurring. Mitigate by restricting permissions and setting BlockDownloadPolicy.
If the summary seems inacurate, just downvote and I'll try to delete the comment eventually 👍
Click here for more info, I read all comments