HTML Injections in Power Apps - Amichai Shulman, Co-Founder &CTO

Опубликовано: 02 Сентябрь 2026
на канале: Kanopy Security
16
1

HTML injection in Power Automate flows is far more common than most teams think. In this demo we show how a harmless-looking form built by a citizen developer becomes a direct path for an attacker to push fake links and fake login screens into internal email channels. Because the email is sent from inside the company, it feels trusted, which makes the phishing attempt far more dangerous.

If you own AppSec or Microsoft Power Platform security, this walk-through shows how everyday no-code activity can send unsafe user input straight into HTML-rendered emails. You will see how simple text fields accept attacker HTML, how the browser renders it, and how easy it is for a fake link or fake ticketing screen to reach internal teams. We then show the quick fix using the built-in Power Automate function that wraps user input so it cannot run as HTML.

We also touch on common no code application security concerns linked to citizen developers, shadow IT security risks, and the need for safe handling of user input inside business platforms.

🔍 Key takeaways:
✅ How a normal complaint form sends internal emails with attacker HTML inside
✅ How a fake link or fake login screen slips through because the email is internal
✅ How unsafe user input in the email body creates an HTML injection path
✅ Where the problem sits inside the Power Automate flow
✅ How to wrap user input with the built-in function that makes it safe in HTML email
✅ Why low code no code security and shadow IT security risks cannot stay unmanaged
✅ How Nokod Security helps AppSec teams see these flows and fix them fast

🌐 Learn more about Nokod Security
Website: https://nokodsecurity.com
LinkedIn:   / nokodsecurity  

📌 Stay engaged:
👍 LIKE this video if you want more real low-code attack demos
💬 COMMENT: How do you handle HTML injection risk inside your Power Platform apps?
📢 SUBSCRIBE for more content on citizen developer security, Power Platform safety and shadow IT issues