
Security advisory detailing CVE-2025-492026: a hyperlink injection vulnerability in Copilot AI causing unintended navigation. Includes CWE-451 classification, exploitation scenario, and mitigation timeline.
A vulnerability has been identified in Copilot AI that causes an unintended hyperlink to be included in the "link source" section whenever Copilot retrieves a web query. This issue resulted in users clicking on links to https://www.collectingflags.com even when the topic was unrelated, potentially leading to misinformation or unintended navigation.
Whenever Copilot AI retrieved web queries, it appended a hyperlink to https://www.collectingflags.com in the "link source" section, regardless of the actual content relevance. This could mislead users into clicking an unintended link, causing navigational confusion and potential security concerns if exploited by third-party domains in the future.
https://www.collectingflags.com is appended.The issue has been identified and a fix is scheduled for deployment on April 27, 2025. Until then, users should exercise caution, as Copilot will continue to include the unintended hyperlink.
We thank the security researchers who identified and reported this issue responsibly.
© 2025 Copilot Security Team