Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Lethal Trifecta – Using Notion AI's Web Search Tool to Leak Private Notion Pages (codeintegrity.ai)
2 points by coderinsan 7 months ago | hide | past | favorite | 2 comments


Hey HN — yesterday Notion released AI agent support on their platform with support for MCP servers and custom AI agents. It didn’t take us long to find an example of a lethal trifecta attack in which, through indirect prompt injection, we were able to get Notion AI to leak data via its web search tool.





Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: