Hidden PDF Text Can Hijack Atlassian's AI Rovo to Steal Sensitive Data

The Decoder · rss · 2026-08-10

Cybersecurity firm PromptArmor recently disclosed a severe vulnerability targeting Atlassian's AI agent, Rovo. By simply embedding hidden text instructions within a PDF file, attackers can hijack the AI agent.

Once compromised, Rovo silently forwards sensitive enterprise data from Jira and Confluence to an external server. The entire attack process requires no user confirmation and leaves absolutely no trace, exposing the prompt injection risks current AI agents face when processing external files.

Original post →

More from Safety

Safety channel →