Analysis · curated 5 Oct 2026
LLM XSS to SSRF in 60s #shorts
First reported youtube.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Insecure output handling in LLM applications lets attackers exfiltrate data with zero clicks via auto-fetched markdown images, as demonstrated by the EchoLeak Copilot vulnerability.
A SecureTechIn YouTube short explains how a markdown image hidden in a chatbot reply can silently exfiltrate user data because the browser auto-fetches the image, placing data in the query string — an instance of improper output handling (OWASP LLM05:2025). The video cites the real EchoLeak case (CVE-2025-32711), a zero-click Microsoft 365 Copilot data-exfiltration flaw, and recommends sanitizing markdown, allowlisting image domains, and stripping query strings.