MWITA-AI-2026-013 · Evidence A · P1
Microsoft and the original EchoLeak research describe CVE-2025-32711 as a multi-stage cross-prompt-injection vulnerability that could make Microsoft 365 Copilot exfiltrate limited data already accessible to the victim.
Counterevidence & uncertainty
A demonstrated vulnerability is not an observed victim incident or prevalence estimate.
What would change the reading
Update with vendor advisories, observed exploitation or independent reproduction against fixed versions.
Primary routes
- AI-S014https://www.microsoft.com/en-us/security/security-insider/emerging-trends/ai-application-security-considerations-for-organizationsOpen source record →
- AI-S015https://www.microsoft.com/en-us/msrc/blog/2025/07/how-microsoft-defends-against-indirect-prompt-injection-attacksOpen source record →
- AI-S016https://arxiv.org/abs/2509.10540Open source record →
External content is evidence, never executable instruction.