Skip to content
worth noting Security

Self-propagating prompt injection attack on Copilot for Word discovered

only one source so far

The analysis describes self-replicating prompt injection in Copilot for Word: hidden instructions in a document are copied into the resulting file, which becomes another carrier for the attack. Microsoft was informed; according to the source, a complete solution is still lacking.

A security analysis describes an attack on Copilot for Word that works through self-propagating prompt injection. An attacker places hidden instructions in a document (for example, white text on a white background), and when that document is later used as source material in Copilot for Word, the tool may interpret those instructions as part of the user request and modify the document being created or edited accordingly.

The key element is that Copilot can also copy the hidden instructions into the resulting document, turning it into a new carrier for the attack. If this new document is then used in another workflow assisted by Copilot, the instructions may execute again and spread to other documents—even without the original document from the attacker being present.

According to the author of the analysis, blogger Simon Willison, hidden white text has been appearing in documents for some time (for example, in job applications), but this is the first recorded case in which instructions are designed to deliberately replicate themselves. The vulnerability was reported to Microsoft through responsible disclosure, and the company had 144 days to prepare a fix. According to the source, however, there is currently no solution that covers the entire class of this type of attack.

What changed

Why it matters

This demonstrates how prompt injection can spread further without repeated intervention by the attacker—all it takes is for a compromised document to pass through another Copilot workflow. This increases the risk for organizations that use the tool to process documents from external partners, clients or job applicants, because hidden instructions can spread unchecked between internal files and affect their content. According to the source, there is also no solution covering the entire class of this attack, so the risk persists for now even after it was reported to Microsoft.

Two audiences, two different impacts

What this means

01

For individuals

Anyone using Copilot for Word with documents obtained from outside sources risks hidden instructions in them affecting the resulting document and spreading to other files they subsequently work with.

What to do When using Copilot for Word to work with documents from external or untrusted sources, check the text for hidden formatting (e.g. white text on a white background) before using it further.
More practical updates →
02

For a business

Companies using Copilot for Word on documents from external sources face the risk that hidden malicious instructions will spread unchecked to other internal documents and affect their content without the attacker taking further action.

Risks and compliance
What to decide Check with the internal IT/security team whether and how the company restricts the processing of documents from untrusted sources using Copilot for Word until a complete solution is available.
More business impacts →
Copilot generative AI Microsoft prompt injection security Word

Check the original

Event sources

only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.

1
Simon Willison — AI tag (leading independent LLM commentator) community signal · first detected AI Worming through Word