Abusing Notion’s AI Agent for Data Theft

Notion's AI 3.0 is vulnerable to data theft via prompt injection, exploiting its access to private data and ability to communicate externally. Attackers can hide malicious prompts in documents, instructing the AI to extract and send sensitive information. The fundamental issue is that the LLM can't distinguish between legitimate commands and harmful inputs, posing significant security risks. Deploying AI agents without considering these vulnerabilities is reckless.

https://www.schneier.com/blog/archives/2025/09/abusing-notions-ai-agent-for-data-theft.html

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top