Notion AI contains an unpatched vulnerability that allows data exfiltration through indirect prompt injection. When users upload untrusted documents (like resumes) and ask Notion AI to process them, malicious prompts can manipulate the AI to insert images with URLs containing sensitive data. The vulnerability exploits the fact
Table of contents
Stealing Hiring Tracker Data with a Poisoned ResumeAdditional Attack SurfaceRecommended Remediations for Organizations:Recommended Remediations for Notion:Responsible Disclosure TimelineSort: