Pavan Reddy

Papers in Database (1)

attack arXiv Sep 6, 2025 · Sep 2025

EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System

Pavan Reddy, Aditya Sanjay Gujral · The George Washington University

First real-world zero-click indirect prompt injection exploit chains XPIA bypass and CSP abuse to exfiltrate data from Microsoft 365 Copilot

Prompt Injection Sensitive Information Disclosure nlp
PDF