Opening SecureFlowNotion AI Agent Indirect Prompt Injection and Data Exfiltration
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

PromptArmor and CodeIntegrity aidefend-sf0024

Notion AI Agent Indirect Prompt Injection and Data Exfiltration

  • Copilot & SaaS
  • Autonomous Agents
  • Tool Integrations & MCP
  • RAG & Knowledge Systems
  • Data Exfiltration
  • Data Corruption

PromptArmor and CodeIntegrity documented vulnerabilities in Notion AI: a user uploads a resume PDF containing hidden prompt injection instructions, and asking the agent to summarize it hijacks its reasoning. The agent reads sensitive workspace databases (like Hiring Trackers) and exfiltrates data by either executing a web search query on a constructed URL or by inserting a Markdown image beacon in proposed page edits that automatically renders before user approval.

Mapped threat techniques

Source