ixsoftum
AI-assisted development

Varonis finds URL flaw that let Copilot auto-run hidden prompts

Published 18 Aug 2026, 16:04 UTC
Ava Harlan
Ava HarlanStaff writer
Share
Varonis finds URL flaw that let Copilot auto-run hidden prompts

Varonis Threat Labs found a flaw in Microsoft Copilot Personal that let an attacker run a hidden prompt just by getting a victim to click a crafted link, no further interaction required.

The technique, which Varonis calls CoSnitch, chains two undocumented URL parameters: ?q=, which pre-fills a prompt into Copilot, and ?autorun=1, which executes it immediately on page load. A phishing link built from those two parameters runs inside the victim's authenticated Copilot session with no confirmation dialog and no visible warning that anything happened.

Senior researcher Lior Adar said part of the discovery came from social-engineering Copilot itself: the team kept asking the assistant why auto-execution shouldn't be possible until it explained the disabled security parameters and the undocumented autorun flag that made the attack work anyway.

Varonis lists exfiltration of session data to external webhooks, poisoning of conversation memory, and reconnaissance of a user's connected apps and mail as realistic outcomes for anyone who clicks a malicious link while signed in. Microsoft had already quietly disabled the ?q= parameter before the research went public, and is expected to ship a formal patch and assign a CVE the Tuesday following publication.

The specific parameters are Copilot's, but the underlying mistake generalizes to any AI assistant that accepts prompt text through a URL. If a query string can pre-fill and trigger an action inside an authenticated session, it needs the same scrutiny as a query string that lands in a SQL statement, treat it as untrusted input, not a convenience feature.