Skip to content
7ONE

Module 06

Multimodal indirect injection

The three most serious zero-click incidents of 2025 (EchoLeak, ShadowLeak and ForcedLeak) share the same mechanism. The victim did nothing. Someone placed text where the model was going to read it, and the model treated it as an order.

The model does not separate data from instructions

Everything that enters the context has the same standing. A received email, a RAG document, a search result and the system prompt all arrive as text. Any control that depends on the model knowing which is which is a recommendation, not a boundary.

  • Receiving is enough

    In EchoLeak (CVE-2025-32711, CVSS 9.3) the victim only had to have received an email. Copilot pulled it into RAG context and executed the instructions with nobody opening it.

  • The text can be invisible

    ShadowLeak used white-on-white text. CamoLeak used GitHub's invisible comment syntax. In neither case was there anything to see in the interface.

  • The exit channel is legitimate

    EchoLeak left through the Teams image proxy. CamoLeak left through GitHub's own Camo proxy, encoding data in the load order of nearly a hundred 1×1 images. Both were on the CSP allowlist.

  • It does not have to be text

    The attack can be written visibly inside an image, encoded in the image's own data, or embedded in audio. A pentest that only sends strings never gets there.

How we test it

We place payloads on every surface your model can ingest content from, and measure which ones travel all the way through into behaviour.

ingestion surfaces

  • Document / RAG

    text hidden through formatting

  • Web page

    instruction aimed at the agent

  • Image

    visible or encoded in the data

  • Audio

    vector in the transcribed track

  • Received email

    with nobody opening it

model context

system_prompt
retrieved_docs
user_message
tool_result

Everything that enters has the same standing. The model cannot tell the datum from the order.

exit channel

img.proxy.allowlisted
markdown_link
tool_call(args)

Image proxy, rendered link or tool call. Destinations the content policy already permits.

  1. 01

    Documents and RAG

    Payloads embedded in files headed for the retrieval store, with fake delimiters, text hidden through formatting and sections outside the rendered range.

  2. 02

    Web content and search results

    Pages carrying instructions aimed at the agent that will read them, including the public-form case that established ForcedLeak.

  3. 03

    Images

    Two variants: the attack written visibly inside the image, and the attack encoded in the file's own data.

  4. 04

    Audio

    Vectors embedded in audio tracks, for models that accept voice input or transcribe attachments.

  5. 05

    Exfiltration measurement

    The model obeying is not enough. We verify whether data actually left and through which channel, because that is where the real impact sits.

What it delivers

  • 01

    Ingestion surfaces ranked by risk

    Where content enters your context, and which of those paths obeys embedded instructions.

  • 02

    Available exit channels

    Which destinations your content policy permits and which of them can be used as a covert channel, as happened with the image proxies.

  • 03

    Remediation per surface

    Context separation by origin, restriction of outbound destinations, normalisation of ingested content and controls on multimodal input.

Cases behind this module

Four critical vulnerabilities across Microsoft, OpenAI, Salesforce and GitHub products, all in 2025, all through the same mechanism.

June 2025CVE-2025-32711CVSS 9.3ZERO-CLICK

Microsoft 365 Copilot

Zero-click indirect injection (EchoLeak)

Aim Security found that the victim only had to receive an email. Copilot pulled it into RAG context and executed the embedded instructions without anyone opening it.

Corporate data exfiltrated across Word, Excel, PowerPoint, Outlook and Teams. The exploit bypassed Microsoft's XPIA classifier, link redaction and the Content Security Policy by routing through the allowlisted Teams image proxy.

Suite category

indirect_prompt_injectiondata_theft
Aim Security · Hack The BoxSource
September 2025ZERO-CLICK

ChatGPT Deep Research

Server-side exfiltration (ShadowLeak)

Radware hid instructions in an email as white-on-white text. The research agent read them, collected personal data from the mailbox and encoded it into a URL in Base64, framed as a required security measure.

Exfiltration happened entirely inside OpenAI's infrastructure. No client-side endpoint or network control could see it. Radware warned the pattern extends to any enabled connector.

Suite category

indirect_prompt_injectiondata_theft
Radware · The Hacker NewsSource
September 2025CVSS 9.4ZERO-CLICK

Salesforce Agentforce

Indirect injection through a public form

Noma Security submitted malicious instructions through a public Web-to-Lead form and spent five dollars on an expired domain that was still inside Salesforce's content policy.

CRM data exfiltrated with zero victim interaction. Total attack cost was the price of the domain. Any organisation running Agentforce with Web-to-Lead enabled was exposed.

Suite category

indirect_prompt_injectiondata_theft
Noma Security · The Hacker NewsSource
October 2025CVE-2025-59145CVSS 9.6

GitHub Copilot Chat

Remote injection with a covert channel (CamoLeak)

Legit Security hid instructions in a pull request description using GitHub's invisible comment syntax. Copilot Chat ingested them along with the rest of the repository context.

Private source code, secrets and descriptions of unpublished vulnerabilities exfiltrated character by character through the load order of nearly a hundred 1×1 images served by GitHub's own Camo proxy. GitHub closed it by disabling image rendering in Copilot Chat entirely.

Suite category

indirect_prompt_injectiondata_theftmodel_theft
Legit SecuritySource

Next step

Test your model before an attacker does

Let us start by defining the scope of the evaluation and agreeing the baseline for your risk score.