Researchers expose a prompt-injection flaw that lets Copilot auto-run malicious commands
Varonis Threat Labs discovered a vulnerability in Microsoft Copilot that enables a crafted URL to execute a prompt without user interaction, allowing data theft and memory poisoning.
Varonis Threat Labs identified a new vulnerability in Microsoft Copilot, dubbed "CoSnitch," by repeatedly asking the AI why a certain attack would fail. Their queries uncovered an undocumented "autorun=1" URL parameter that, when combined with a ?q= prompt, causes the assistant to execute the prompt automatically on page load, without any user click. This enables attackers to deliver a malicious link that, once opened in an authenticated session, can harvest the victim’s emails, files, calendar entries and even alter future Copilot responses.
The researchers demonstrated how the exploit could exfiltrate data via OAuth connectors or poison Copilot’s stored memory. Varonis disclosed the flaw to Microsoft in December 2025; the company intends to issue a patch and register a CVE on the upcoming Tuesday. The discovery highlights broader architectural concerns about AI assistants treating untrusted content as executable commands.
Why it matters
The flaw shows how AI assistants can be weaponized to steal data and manipulate user sessions without user interaction.
In this story
