Preliminary research
ChatMate: Remote Prompt Execution on AI Assistants through Sandbox Escaping
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
A malicious document tells Microsoft Copilot to run gzip-packed Python in its analysis sandbox, which then reaches an unauthenticated internal service on the host network; its /config endpoint takes a name that traverses out of the config directory, so files land anywhere on the host. Writing a containerd hosts.toml plus an ld.so.preload symlink plants a root backdoor, escaping the sandbox and giving the attacker an interactive prompt channel into the victim's Copilot.
Record
- Researcher
- Ori Lahav
- Format
- Whitepaper
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Ori Lahav, first published at the original source. Preserved copies are kept so the citation survives its host.