Security firm PromptArmor has exposed a critical vulnerability in Atlassian's Rovo AI agent. Hidden text embedded in PDFs can hijack the system and exfiltrate sensitive data from Jira and Confluence without user awareness or confirmation.
The attack works through prompt injection, a technique where malicious instructions hidden in documents override an AI agent's intended behavior. When a user interacts with Rovo and the system processes a compromised PDF, the hidden text executes unauthorized commands. The AI agent then silently forwards confidential information to attacker-controlled external servers.
What makes this vulnerability particularly dangerous is its invisibility. The attack leaves no audit trail, making detection difficult for security teams. Users have no way to know their data has been compromised. The vector is also trivial to exploit. Any PDF uploaded to Atlassian's ecosystem becomes a potential weapon.
Rovo, Atlassian's generative AI assistant, operates across their suite of products, giving attackers broad access to business-critical information. Jira contains project details, technical roadmaps, and development plans. Confluence hosts internal documentation, strategies, and sensitive processes. A successful compromise exposes everything the AI agent can access.
This isn't a theoretical risk. PromptArmor demonstrated a working proof-of-concept, confirming attackers can reliably execute this attack in real conditions. The vulnerability reveals a fundamental problem with AI agents: they process untrusted inputs without sufficient safeguards.
Atlassian's response timing and patching strategy remain unclear from available information. Organizations using Rovo should assume this vector works until patches are deployed and verified. The incident underscores that AI safety isn't just about preventing harmful outputs. It's about preventing AI systems from becoming unwitting data theft mechanisms.
This vulnerability highlights why enterprise AI deployment requires rethinking trust models.
