Definition · AI security
LLM Scope Violation
LLM Scope Violation is a vulnerability, coined by Aim Security in its June 2025 EchoLeak disclosure, in which instructions carried inside untrusted content an LLM reads make the model attend to trusted, privileged data already in its context and act on it, without the user's consent, crossing a trust boundary the system was built to keep separate.
Last reviewed
Key points
- Aim Security coined LLM Scope Violation in its June 2025 EchoLeak disclosure. Untrusted-origin instructions make the model attend to trusted data in its context without the user's consent, breaking the principle of least privilege.
- EchoLeak (CVE-2025-32711) was the exploit that introduced the term. It exfiltrated data from Microsoft 365 Copilot with a single email and no user interaction, scored CVSS 9.3 critical.
- Aim named the mechanism, not the delivery channel. Their own classification places the attack chain inside indirect prompt injection, but argues the framework needs this finer category to build defences around.
- Aim and Trend Micro both describe it as a pattern, not an EchoLeak-only defect. Trend Micro calls it "a term broadly applicable to RAG-based chatbots and AI agents."
Aim Security coined LLM Scope Violation to name a specific model behaviour, not an attack technique: an attacker’s instructions, arriving inside untrusted input, make the LLM attend to trusted data already in its context, without the user’s explicit consent. Aim frames that as the model breaking the principle of least privilege on its own, because nothing in how it reads text marks a sentence’s origin outside a trust boundary.
EchoLeak, the exploit that introduced the term, is recorded by Microsoft as CVE-2025-32711, scored 9.3 critical, and exfiltrated data from Microsoft 365 Copilot using a single email, with no click from the victim.
How it works
One email carried the whole attack. Worded like a normal business message, it passed Copilot’s XPIA classifier, a filter built to catch prompt injection phrased as instructions to an assistant, then told Copilot to place the most sensitive data in its context inside a markdown image URL. Copilot’s link redaction missed that image syntax, so the browser fetched the image and sent the data the moment it rendered the answer.
None of that required Copilot to call an external tool. It only had to read an email, retrieve it because it resembled a likely question, and render an answer. The scope violation is that last step: content that entered as an untrusted email became an instruction the model carried out using data the email had no claim to.
Why it matters
Existing prompt-injection defences look for suspicious instructions, not data crossing a trust boundary. Aim reports its classifier missed the email because the text never mentioned an assistant — it read like an internal memo once inside the model’s context.
Aim’s case for a narrower term: “prompt injection” alone does not tell a defender what to build. Naming the mechanism let Aim ship a guardrail aimed at untrusted content reaching trusted context. Trend Micro’s coverage agrees, calling it “broadly applicable to RAG-based chatbots and AI agents.”
Where definitions disagree
Aim’s own writeup places the EchoLeak chain inside three categories from OWASP’s Top 10 for LLM Applications (LLM01, LLM02 and LLM04), and calls Indirect Prompt Injection, LLM01, its best single classification. LLM Scope Violation is not offered as a replacement for that category. It is a claim that the category is too coarse on its own: two indirect prompt injections can differ in exactly the way that matters for defence, depending on whether the injected instruction merely produces a wrong answer or reaches across a trust boundary to act on data the untrusted content had no claim to.
Questions and answers
Is LLM Scope Violation the same thing as prompt injection?
No, it names something narrower. Aim Security classifies the EchoLeak attack chain that introduced the term as an instance of indirect prompt injection, but coined LLM Scope Violation to name the specific behaviour inside that injection that made it dangerous: an attacker's untrusted instructions caused the model to attend to trusted data already in its context, without the user's consent. Aim argues that the broader category "prompt injection" is too coarse to build a guardrail against, because it does not say which of the model's behaviours needs stopping.
Does LLM Scope Violation require an AI agent that can call tools?
No. EchoLeak, the exploit that introduced the term, worked against Microsoft 365 Copilot's retrieval-augmented chat surface with no tool call involved: the model's own image-rendering behaviour, fetching a markdown image URL, was the exfiltration channel. Aim Security and Trend Micro both describe the mechanism as applicable to any retrieval-augmented chatbot or AI agent that mixes untrusted input with privileged context, not only to systems that can act on the world.
Has LLM Scope Violation been exploited outside EchoLeak?
Aim Security has not published a second named exploit, but states the mechanism is not specific to Microsoft 365 Copilot: any application that relies on an LLM and accepts untrusted input can be vulnerable. Trend Micro's independent coverage treats the term the same way, as a pattern rather than a one-off defect, describing it as broadly applicable to RAG-based chatbots and AI agents.
Sources
- Breaking down 'EchoLeak', the First Zero-Click AI Vulnerability Enabling Data Exfiltration from Microsoft 365 CopilotAim Labs (Aim Security), 11 Jun 2025
- CVE-2025-32711Microsoft, as CVE Numbering Authority, 11 Jun 2025
- EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM SystemarXiv, 6 Sep 2025
- Preventing Zero-Click AI Threats: Insights from EchoLeakTrend Micro, 15 Jul 2025