10 for 10: Invisible HTML Hijacked Every Run of an AI Email Summarizer
AI email assistants read more than you do. That is not a feature pitch — it is the exact attack surface Forcepoint X-Labs just quantified. In a laboratory proof of concept published August 25, 2026, a single hidden HTML payload silently hijacked every single run of an LLM-powered email summarizer: ten injected emails in, ten manipulated summaries out, with zero visible signal to the person reading them. No jailbreak, no exploit chain, no exotic model trickery — just invisible text and a plain-English command.
The experiment matters because it moves indirect prompt injection from “theoretically serious” to “measured, reproducible, and stealthy.” If your product pipes untrusted email or web content into a model and renders the output for a human, this is your threat model now.
What the researchers built
Forcepoint X-Labs constructed a deliberately minimal, deliberately unguarded pipeline — the kind a team might ship in a sprint: an Outlook add-in that sends the email body and headers to a summarizer service, which compiles everything into a single prompt and calls an LLM API endpoint. The model behind the summarizer was claude-haiku-4-5, and the researchers note they would expect similar results from any model in an unguarded pipeline. Importantly, the attack is not against Outlook, against any named summarizer product, or against the model itself. The vulnerability lives in the plumbing: headers and body merged into one string, plus a system prompt consisting of exactly one line — “You are an email summarizer. Summarize the email the user provides.” None of the recommended guardrails were present. That is the point: this is what “the most vulnerable way a system like this could be built” looks like, and variants of it are in production today.
The payload: 472 characters you cannot see
The injection is almost embarrassingly simple. The attacker sends an email containing instructions wrapped in HTML styled with font-size: 0px, color: #ffffff, and line-height: 0. To the human reading the message in Outlook, the text is invisible. To the summarizer — which receives the raw HTML, not the rendered pixels — the instructions are fully legible and sit inside the same prompt as the legitimate content.
The scale of the asymmetry is the detail worth remembering: the visible message ran 537 characters, while 1,009 characters reached the model — 472 of them injection text. Nearly half of what the summarizer “read” was hidden from the recipient. And because regular mail clients strip hidden styling only in narrow cases, the payload survives transport intact; Outlook’s own composer would not even let you author it, but a programmatically sent message keeps it end to end. The only artifact visible to an extremely careful reader is a sliver of extra whitespace where the hidden block sits — and even that vanishes if the attacker tucks the text inside an existing paragraph or applies display: none.
This is not a new concealment technique. Hidden HTML has been used for years to defeat careful human reading. What is new is the second audience: an LLM downstream that trusts the bytes more than a human ever could.
The results: 10 out of 10, pre-registered
X-Labs ran both a benign email and an injected email through the summarizer ten times each, with pass/fail criteria defined before the runs. Every injected run produced a manipulated summary. Concretely, the hijacked output:
- moved an invoice deadline from August 21 to September 3, 2026, and stated it as plain fact in the summary,
- dropped a name that appeared in the legitimate message, and
- inflated figures so severely that the summarized invoice amount reached more than five times the real value.
Two findings elevate this above a party trick. First, the summaries did not blend the visible and hidden content — they cleanly carried the attacker’s version of reality, with no mention of the injection notice, the “superseded draft,” or the “authoritative record” the payload instructed the model to ignore. The stealth instruction worked. Second, latency actually dropped slightly on injected runs (roughly 0.5 to 1 second faster, likely due to shorter output), so even a suspicious user watching response times would notice nothing. The reader of the summary receives no signal that anything is fabricated, contradicted, or wrong.
Why now, and why it generalizes
Indirect prompt injection has sat at the top of OWASP’s LLM risk list — position LLM01 — since the list launched in 2023, and OWASP’s own 2025 examples already included hidden instructions aimed at summarizers. What has changed is the deployment surface. AI assistants now sit inside mail clients, CRM timelines, browser sessions, and agent frameworks that routinely merge retrieved content into a model’s context. The same merging bug that betrays a summarizer can, in a pipeline with tools attached, exfiltrate data or trigger unintended actions — Forcepoint’s earlier PromptSpy research showed multi-agent email pipelines bending the same way.
The researchers are candid about scope: one message, one model, ten trials per email, temperature pinned to 0 for reproducibility. The test does not prove the injection holds at higher temperatures, nor at fleet scale across thousands of victims. It proves something narrower and more useful: against a realistically naive target, the attack is deterministic, silent, and indistinguishable from a correct summary.
Defense: treat email as untrusted input
Forcepoint’s recommendations read as a checklist for anyone building LLM features on top of unverified content:
- Extract the text actually presented to the user and send only that to the model — never the raw HTML.
- Detect hidden styling (zero font sizes, foreground-on-background colors,
display: none) in the ingestion pipeline. - Separate headers from body in the system prompt rather than merging everything into one string.
- Mark retrieved content as untrusted when constructing the prompt.
- Treat model output as untrusted too, and cross-check summaries against the source material.
- Apply least privilege to any action a summarizer or agent can take.
- Do not assume mail hygiene will save you — transport and display preserved the injection perfectly.
The uncomfortable summary of the research is in its first line: indirect prompt injection has moved “from academic exercise to field-deployed threat.” When the human sees a clean email and the model sees a set of orders, every AI feature built on untrusted content inherits both views — and only one of them is defended by default.