CVE-2024-49038: Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorize
criticalvulnerabilityLLM-Specific
security
Summary
CVE-2024-49038 is a cross-site scripting (XSS, a type of attack where malicious code is injected into a webpage to trick users) vulnerability in Microsoft Copilot Studio that allows an unauthorized attacker to gain elevated privileges over a network by exploiting improper handling of user input during webpage generation.
Vulnerability Details
CVSS Score
9.3(critical)
EPSS (30-day exploit probability)
EPSS: 0.2%
Classification
Attack Type
Jailbreak
Attack SophisticationModerate
Impact (CIA+S)
integritysafety
Affected Vendors
Microsoft
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-49038
First tracked: February 15, 2026 at 08:51 PM
Classified by LLM (prompt v3) · confidence: 85%