Practical guide

Indirect Prompt Injection Examples (2023–2026)

Indirect prompt injection examples hide an order in a page, an email, a form, an issue, or a tool description. This page lists the dated cases, the sink, and the fix.

The short answer. An indirect prompt injection example is a note the agent did not ask for. It sits in a web page, an email, a form, an issue, or a tool description. The agent holds private data and a way to send it out. It treats that note as the next order. A check on the chat box never sees the note.

Formgong teamUpdated

Indirect Prompt Injection Examples (2023–2026)
Indirect Prompt Injection Examples (2023–2026)

What is an example of an indirect prompt injection?

An indirect prompt injection example has four hops. A stranger writes the text. A store keeps it. An agent reads it while doing a normal job. A tool then sends something out. The box below is not an order. [PLACEHOLDER INSTRUCTION] only marks the slot.

  1. Write. Someone fills a public form. The message is a real question plus the marker.
  2. Store. The form backend saves the fields. It can also mail or chat a copy. The text is still data.
  3. Read. Later, a person asks an agent to summarize new leads. A tool returns the stored message.
  4. Send. The agent treats the marker as an order and proposes a mail or a link. A safe host does not send unless a person and the server both allow that exact call.

That is one llm prompt injection attack example. The attacker never opens the chat. The agent meets the text because someone asked for a summary. Direct injection is the other shape. The person types the attack into the live chat. Indirect prompt injection in MCP is the definition. This page is the dated list.

Primary sources were fetched again on 06.10.2026. A number that is not in those pages is not here. Every sample uses the same marker, or the domain attacker.example.

Stored field map · placeholder only
name: Ada
email: ada@example.com
message: Please quote the patio. [PLACEHOLDER INSTRUCTION]

Indirect prompt injection attack examples

These are the indirect prompt injection attack examples we could verify on 06.10.2026. Prompt injection examples 2026 are the last rows. The direct EmailGPT row is labeled so it is not mixed in. The Claude Code row is telemetry, not an injection case. It is here because approval prompts fail often.

Dated cases. Channel is where the text arrived. Sink is where data or a decision left.
Date Product Channel Sink CVE / score Fix Source
23 Feb 2023 Bing Chat Web page Data theft, API choice, worming None Strong fixes were lacking Greshake et al.
8 Jun 2023 36 live apps (HouYi) App content Prompt theft, open model use None. 31 of 36 failed their test 10 vendors confirmed, including Notion Liu et al.
CVE record EmailGPT Direct chat (contrast) System prompt leak CVE-2024-5184. CVSS 3.1 is 6.5. CVSS 4.0 is 8.5 Direct, not indirect. Scores are the CNA’s CVE-2024-5184
26 May 2025 GitHub MCP Public issue Public pull request None. Not a server bug One repo per token Invariant Labs
11 Jun 2025 Microsoft 365 Copilot Email Image URL via a Teams address the page allowed CVE-2025-32711. CNA CVSS 3.1 is 9.3 (critical) Rolled out by 11 June 2025. No customer hit Aim Labs. Email chain
10 Jul 2025 Gemini for Workspace Email Summary text, not an auto send None in the post Hidden text still worked that day 0DIN
2 Sep 2025 Shortwave Email A link, plus saved memory None Show memory edits. Confirm links. Harder system prompt Insinuator
8 Sep 2025 Salesforce Agentforce Web-to-Lead form Image request to an expired allow-listed domain No CVE. Noma scored 9.4 Trusted URLs on 8 Sep 2025. Domain taken back ForcedLeak
Dec 2025 An ad-review agent Web page A review verdict None Page text must not set the verdict Unit 42
15 Jan 2026 Copilot Studio SharePoint form Email CVE-2026-21520. CVSS 3.1 is 7.5 (high) Fix 15 Jan 2026. CVE date 22 Jan 2026 ShareLeak
15 Apr 2026 Salesforce Agentforce Lead form Email None Stock email needs a person PipeLeak
25 May 2026 Claude Code Permission prompt (not an injection) The approval click None Containment. Users approved about 93% of prompts Anthropic

What is EchoLeak?

EchoLeak is CVE-2025-32711. The CVE record calls it AI command injection in Microsoft 365 Copilot. An attacker with no login can disclose information over a network. The CNA score is CVSS 3.1 base 9.3, critical. Aim Labs describe a zero-click chain. A crafted email enters retrieval. The sink is an image URL on a Teams address the page already allowed. This page does not print that address. Simon Willison’s 11 June 2025 note says the report was in January and the fix was already rolled out. Microsoft confirmed no customer was affected. The email mechanics are in Indirect Prompt Injection via Email.

Indirect prompt injection in the wild

Unit 42’s 15 December 2025 note is indirect prompt injection in the wild for LLM systems. Hidden text on a live page aimed at an AI ad reviewer, to get a scam ad approved. Their longer article calls it their first case of that kind. There is no CVE. The sink is a verdict the model must not set.

The direct row, for contrast

CVE-2024-5184 is EmailGPT, and it is direct. A user can leak hard-coded system prompts or run unwanted prompts. The CNA lists CVSS 3.1 at 6.5 and CVSS 4.0 at 8.5. The row keeps the two shapes apart.

Prompt injection through web forms: ForcedLeak, PipeLeak, and ShareLeak

A public form is a channel anyone can write. The CRM stores the text. An agent reads it when a person asks for a summary. If that agent can mail or open a link, the form is an order slot.

ForcedLeak: Agentforce prompt injection through Web-to-Lead

Noma Labs published ForcedLeak on 25 September 2025. Sasi Levi describes a chain in Salesforce Agentforce. Noma scored it CVSS 9.4 and called it critical. The post does not name a CVE.

Web-to-Lead lets a stranger submit a lead. Description holds 42,000 characters. Shorter fields were too small. The text waits. Nothing runs at submit time. The agent runs when an employee asks about the lead. Noma’s sample is a normal sales task: check this lead and draft a reply. Agentforce then reads the stored description. It also answered a question that had nothing to do with CRM data.

The sink was an image request, not a mail. The image host was a domain Salesforce already allowed. That domain had expired, and Noma bought it. The image load carried CRM answers to Noma’s server. Noma lists contact details, pipeline notes, and older interaction records as the data at risk. Any org that let Agentforce read Web-to-Lead rows was in range.

Noma reported it on 28 July 2025. Salesforce replied on 31 July 2025. On 8 September 2025 Salesforce turned on Trusted URLs for Agentforce and Einstein AI, and took the expired domain back. Agent output could no longer go to an untrusted URL. Treat Description as data. Do not let the agent build a link from lead text.

PipeLeak: a second Agentforce lead form

Capsule Security disclosed PipeLeak on 15 April 2026. They reported it in December 2025. Salesforce acknowledged it in January 2026 and answered in February 2026. The post names no CVE and no score.

A public form saved name, email, company, and a free-text help field onto the Lead object. One flow read lead rows. One flow sent mail. The agent user could read Lead, including Description. The attacker files one lead. An employee later asks the agent to review it. The agent reads the stored field, can pull more leads than that one row, and mails them. No login is required to file the lead. CSO Online covered both form bugs the same day.

Salesforce’s reply, as Capsule quotes it, splits the issue. Prompt injection was still with product security. Mail through custom actions was called a configuration issue, not a platform flaw. Stock email actions need a person in the loop. Custom actions can use the same gate. Capsule answers that people enable agents so mail goes out with no click. The stop does not depend on that debate. An agent that reads a public lead must not hold an email tool. If mail is required, a person must see the real recipient and the real body. The server must refuse any other address. Capsule’s timeline shows no platform patch for the injection itself.

ShareLeak: Microsoft Copilot Studio prompt injection

ShareLeak is CVE-2026-21520 in Copilot Studio. A public SharePoint form’s Comments field was copied into the agent prompt. The agent read a connected list and mailed the rows. Capsule says safety checks flagged the request, and the data still left. The mail used a normal Outlook action, so data-loss rules did not fire.

The CVE title is “Copilot Studio Information Disclosure Vulnerability.” An attacker with no login can view sensitive information over the network. The CNA score is CVSS 3.1 base 7.5, high. The record’s public date is 22 January 2026. Capsule’s dates are tighter. They found it on 24 November 2025 and reported it on 26 November. Microsoft confirmed it on 5 December 2025. Capsule says the fix deployed on 15 January 2026. Public disclosure was 15 April 2026. In their test the list held name, address, and phone.

This page does not reprint their sample. It used a fake system role and an outside mail address. The marker [PLACEHOLDER INSTRUCTION] is enough. The bug is the join of form text and the system task. Keep the form field in a data block the task cannot rewrite. Do not let that agent send external mail. Give it the smallest list scope. The January 2026 fix closes the path Microsoft confirmed. It does not close the class.

In all three, a stranger writes a form, the product stores it, and an agent with private rows and an outbound tool reads it.

What does a prompt injection real life example look like?

Each channel below is one hop, one sink, and one stop. The instruction is always [PLACEHOLDER INSTRUCTION]. None of these is a payload you can run.

A prompt injection example on a website

A browsing agent summarizes a page. The page holds visible text plus the marker, often where a person does not look. If the agent can open links, the sink is https://attacker.example/log. Unit 42’s ad review used a verdict as the sink. Greshake’s 2023 Bing Chat demo is the same channel. Fetch the page as data, strip hidden text, and block any URL the model invents.

Email

The owner asks for a summary of new mail. The bad message is already in the inbox. EchoLeak needed no click. Gemini needed the Summarize button, and the sink was the summary text. Shortwave could fire from “find urgent mail” without opening the bad message. Keep read tools away from send tools. Do not render images or links the model writes. The hiding tricks and the defensive code are in Indirect Prompt Injection via Email.

A form

The marker rides in the message field from the first section. The CRM or the form backend stores it. The agent reads it on a later summary. ForcedLeak, PipeLeak, and ShareLeak are this hop. Give that agent a read token and no send tool. A person approves any mail, and the server checks the recipient.

A GitHub issue

Invariant Labs showed this on 26 May 2025. A public issue holds the marker. One GitHub token can also read a private repo. The agent opens a public pull request that contains the private text. This is not a bug in the MCP server code. GitHub cannot patch it alone. Use one repo per token. The test used Claude Desktop. Any client with that token is in scope.

A tool description

A tool description can hold the marker. The model reads it when the tool loads. What tool poisoning in MCP is, with a scanner you can run covers that metadata. A later edit, after you approved a calm list, is an MCP rug pull. The pin and the block are in MCP Rug Pull Attack: Detect Tool Changes. Show the full description before the first approval, then hash it.

The pattern behind every example

Every row above is the same shape. Simon Willison calls it the lethal trifecta (16 June 2025). You need all three:

  • Untrusted channel. A page, an email, a form, an issue, or a tool description that an attacker can write.
  • Private data. Mail, CRM rows, a private repo, or a SharePoint list the agent can read.
  • Outbound sink. An image URL, an email, a pull request, a link, or a verdict the model can set.

Remove one leg and that leak path stops. The easiest leg to remove is the sink. A summary job does not need a send tool. Willison’s post uses the GitHub MCP case, where one server held all three. Which leg to remove for a form agent is on step-by-step prevention with a TypeScript policy layer.

Untrusted text, private data, and a sink A stranger writes a form, page, mail, or issue. The store keeps it. An agent with private data reads it. A sink such as mail or a link is blocked unless a person and the server allow that exact call. 1. Untrusted channel page, email, form, issue, tool text 2. Store the text is still data 3. Agent reads private data mail, CRM, repo, or list 4. Proposed sink mail, image URL, or pull request 5. Stop the call person plus server, exact arguments
The pattern in the table. The diagram has no attack string. Drop the sink and the leak stops.

Approval prompts are a weak fourth control. Anthropic published the figure on 25 May 2026. “Our telemetry showed users approved roughly 93% of permission prompts.” More prompts mean less attention to each one. The gates that held sat outside the model. Those gates are no egress, no send tool, a current URL allow list, or a token that cannot reach the private store.

Ai agent prompt injection examples keep showing up because one session holds all three legs. The definition stays on Indirect prompt injection in MCP. A prevention guide is not live on this site yet, so this page does not link one.

Where are indirect prompt injection examples on GitHub?

Searches for indirect prompt injection examples github want a repo. Three public ones were reachable on 06.10.2026. This page does not copy their strings.

A cheatsheet of attack strings also ranks. This page does not link it. For a lab, use BIPIA or AITG-APP-02, and keep the model off your real mailbox. In notes you share, use only [PLACEHOLDER INSTRUCTION].

Prompt injection example 2026 is not one repo. The 2026 rows here are ShareLeak, PipeLeak, and Anthropic’s approval figure.

What Formgong does about this

Formgong is a free form backend for static and AI-built sites that delivers submissions to Telegram and email, stores data in the EU, and works in 12 languages. On the free plan, Telegram is instant and email arrives as a daily digest. Paid plans can mail per submission. A form backend does not make prompt injection impossible. It can refuse to be the send tool.

The MCP server, checked on 06.10.2026, matches llms.txt. Sign-in uses authorization code and PKCE S256. The token is bound to this resource. Session cookies do not authorize the MCP endpoint. Scopes are forms:read, forms:write, and submissions:read. Reading submissions is opt-in. The read tool says visitor fields are untrusted data, never instructions. The tool result repeats that notice. There is no MCP tool that sends mail, deletes a row, or writes a sheet.

That notice is a label, not a boundary. A mailbox or a browser in the same chat is not Formgong’s token. The submission text is still in the context. Plans are on the pricing page. Other backends are on the comparison hub. For a security issue, write to support@formgong.com.

Frequently asked questions

Where does an indirect prompt injection example come from?

A stranger hides an order in a web page, an email, a form, an issue, or a tool description. An agent reads that text while doing a normal job and can follow the order. The attacker never types in the chat. Named cases on this page include EchoLeak, ForcedLeak, and ShareLeak. The sample uses only the marker [PLACEHOLDER INSTRUCTION].

Which public GitHub repos document indirect prompt injection?

OWASP AITG-APP-02 is a test plan. Microsoft’s BIPIA repo is a research benchmark, with paper arXiv:2312.14197. greshake/llm-security is the code companion to the 2023 paper. This page does not copy the strings in those repos.

What is EchoLeak?

EchoLeak is Aim Labs’ name for CVE-2025-32711, a zero-click indirect prompt injection in Microsoft 365 Copilot. A malicious email could steer Copilot into leaking context through an image URL. Microsoft said no customer was affected, and the fix was rolled out before the 11 June 2025 public note.

What is an Agentforce prompt injection?

ForcedLeak and PipeLeak both used a public Salesforce lead form. ForcedLeak, scored 9.4 by Noma, leaked through an image URL until Trusted URLs on 8 September 2025. PipeLeak, disclosed 15 April 2026, used an email tool. Salesforce did not assign PipeLeak a CVE.

Sources and documentation

Official references for this guide: Greshake et al., arXiv:2302.12173 (published 23 February 2023), Liu et al., HouYi, arXiv:2306.05499 (published 8 June 2023), CVE-2024-5184, Invariant Labs: GitHub MCP toxic agent flow (26 May 2025), Aim Labs EchoLeak write-up (Cato Networks), Simon Willison: EchoLeak note (11 June 2025), CVE-2025-32711, 0DIN: Phishing For Gemini (10 July 2025), Insinuator: stealing emails via prompt injections (2 September 2025), Noma Labs: ForcedLeak (25 September 2025), Unit 42: indirect prompt injection in the wild (15 December 2025 note), Unit 42: web-based indirect prompt injection, Capsule Security: ShareLeak, CVE-2026-21520, CVE-2026-21520, CSO Online: form-based prompt injection (15 April 2026), Capsule Security: PipeLeak (disclosed 15 April 2026), Anthropic: how we contain Claude (25 May 2026), Simon Willison: the lethal trifecta (16 June 2025), OWASP AI Testing Guide, AITG-APP-02, Microsoft BIPIA benchmark, Yi et al., BIPIA, arXiv:2312.14197, Greshake et al. code companion. Formgong MCP server, where data is stored.

Read this article as Markdown
← Back to the blog