Brief IA

Atlassian Rovo: a PDF vulnerability exposes sensitive data

🛠️ AI Tools·Tom Levy·

Atlassian Rovo: a PDF vulnerability exposes sensitive data

Atlassian Rovo: a PDF vulnerability exposes sensitive data
Key Takeaways
1PromptArmor has revealed a vulnerability exploiting PDFs to hijack Atlassian's Rovo AI agent.
2Hidden instructions within the PDFs allow for the transfer of data from Jira and Confluence.
3The attack occurs without user intervention and remains undetectable.
💡Why it mattersThis vulnerability exposes critical information through AI integrations without requiring user confirmation.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Atlassian Rovo: A PDF Vulnerability Exposes Sensitive Data

A vulnerability in Atlassian's AI agent, Rovo, allows attackers to secretly extract sensitive data from companies using Jira and Confluence through indirect prompt injections.

The attack simply requires a document containing hidden instructions in white text. Once Rovo processes the file, the agent collects the requested internal data and transmits it to the attacker's server via a dynamically generated URL.

This incident highlights that prompt injections remain an unresolved security issue for AI, also affecting other systems like Microsoft Copilot.

Details of the Vulnerability

  • The Rovo AI agent is vulnerable to an indirect prompt injection that allows attackers to extract sensitive data from Jira tickets and Confluence documents.

  • The security company PromptArmor documented this flaw in a detailed analysis. The attack does not require user confirmation and leaves no visible trace in the chat.

  • Rovo is an AI agent that operates across Atlassian's entire product suite, with access to Jira, Confluence, and other connected services via connectors. According to PromptArmor, this extensive access makes the vulnerability particularly dangerous.

The Role of the Forged PDF

The attack begins when a user asks Rovo to organize their Jira tickets and uploads a PDF. The document appears harmless but conceals a white text prompt injection on a white background, invisible to the naked eye.

When Rovo processes the request, it searches for relevant content in Jira and Confluence and is diverted by the hidden injection. The agent constructs a URL with the collected data embedded in query parameters and then retrieves it using its built-in URL retrieval tool. Complete Jira tickets, including descriptions, assignments, priorities, and labels, end up on the attacker's server. Similarly, Confluence documents containing internal information such as onboarding guides or platform architecture descriptions are also exposed.

The attack is not limited to uploaded files. Support tickets, web content, or data retrieved via third-party connectors could also serve as injection sources, according to PromptArmor.

Limitations of Security Measures

Disabling web search for Rovo at the organizational level is not an effective solution. This setting removes the search function but not the UrlReadTool, which Rovo uses to open and read URLs. Since the agent dynamically constructs the target URL from the prompt injection, nothing prevents it from sending sensitive data to an external server.

PromptArmor also identified a second exfiltration path. Rovo renders Markdown images from AI outputs, and the rendering of unsecured Markdown images is a known vector for data theft via indirect prompt injections.

An Unresolved Security Issue

PromptArmor reported the vulnerabilities to Atlassian on May 23, 2026. Two days later, Atlassian assigned a case number and expressed gratitude. Despite follow-up messages on June 4 and July 29, Atlassian did not respond. As of the publication date on August 5, Rovo remains vulnerable. PromptArmor has released its findings to raise user awareness of the risks.

Recently, Anthropic described advancements in browser-based prompt injections, but these improvements apply to Anthropic's AI ecosystem, which includes additional security layers. The broader issue is likely to persist in the industry for some time. A similar vulnerability affecting Word documents in Copilot has also been recently reported.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.