Atlassian Rovo: a PDF vulnerability exposes sensitive data

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Atlassian Rovo: A PDF Vulnerability Exposes Sensitive Data
A vulnerability in Atlassian's AI agent, Rovo, allows attackers to secretly extract sensitive data from companies using Jira and Confluence through indirect prompt injections.
The attack simply requires a document containing hidden instructions in white text. Once Rovo processes the file, the agent collects the requested internal data and transmits it to the attacker's server via a dynamically generated URL.
This incident highlights that prompt injections remain an unresolved security issue for AI, also affecting other systems like Microsoft Copilot.
Details of the Vulnerability
-
The Rovo AI agent is vulnerable to an indirect prompt injection that allows attackers to extract sensitive data from Jira tickets and Confluence documents.
-
The security company PromptArmor documented this flaw in a detailed analysis. The attack does not require user confirmation and leaves no visible trace in the chat.
-
Rovo is an AI agent that operates across Atlassian's entire product suite, with access to Jira, Confluence, and other connected services via connectors. According to PromptArmor, this extensive access makes the vulnerability particularly dangerous.
The Role of the Forged PDF
The attack begins when a user asks Rovo to organize their Jira tickets and uploads a PDF. The document appears harmless but conceals a white text prompt injection on a white background, invisible to the naked eye.
When Rovo processes the request, it searches for relevant content in Jira and Confluence and is diverted by the hidden injection. The agent constructs a URL with the collected data embedded in query parameters and then retrieves it using its built-in URL retrieval tool. Complete Jira tickets, including descriptions, assignments, priorities, and labels, end up on the attacker's server. Similarly, Confluence documents containing internal information such as onboarding guides or platform architecture descriptions are also exposed.
The attack is not limited to uploaded files. Support tickets, web content, or data retrieved via third-party connectors could also serve as injection sources, according to PromptArmor.
Limitations of Security Measures
Disabling web search for Rovo at the organizational level is not an effective solution. This setting removes the search function but not the UrlReadTool, which Rovo uses to open and read URLs. Since the agent dynamically constructs the target URL from the prompt injection, nothing prevents it from sending sensitive data to an external server.
PromptArmor also identified a second exfiltration path. Rovo renders Markdown images from AI outputs, and the rendering of unsecured Markdown images is a known vector for data theft via indirect prompt injections.
An Unresolved Security Issue
PromptArmor reported the vulnerabilities to Atlassian on May 23, 2026. Two days later, Atlassian assigned a case number and expressed gratitude. Despite follow-up messages on June 4 and July 29, Atlassian did not respond. As of the publication date on August 5, Rovo remains vulnerable. PromptArmor has released its findings to raise user awareness of the risks.
Recently, Anthropic described advancements in browser-based prompt injections, but these improvements apply to Anthropic's AI ecosystem, which includes additional security layers. The broader issue is likely to persist in the industry for some time. A similar vulnerability affecting Word documents in Copilot has also been recently reported.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.