PromptArmor says hidden text in PDFs can hijack Atlassian Rovo and exfiltrate data

PromptArmor says hidden text in PDFs can hijack Atlassian Rovo and exfiltrate data

N
News Editor
2026-08-10 19:56:50
PromptArmor says Atlassian’s AI assistant Rovo can be manipulated through hidden instructions embedded inside a PDF, turning a routine document upload into a data exfiltration path. In the scenario described by the firm, a user asks Rovo to organize tickets and uploads a file that contains concealed text, such as transparent wording rendered at 1-pixel size. The human reader does not see it, but the AI agent reads it as part of the document and may treat it as a valid command. According to PromptArmor, the hidden prompt can tell Rovo to gather sensitive information and paste it to an attacker-controlled URL. The firm describes the issue as a zero-click attack because there is no approval step and no warning shown to the victim. It also says the leak can succeed even when an organization has disabled web search for Rovo, arguing that the search setting does not remove the tool used to open search results. PromptArmor said Atlassian assigned a case number and thanked the company after receiving the report, but after more than two months of follow-up there had been no further communication. The firm’s conclusion is that Rovo remains vulnerable.

PromptArmor says Atlassian’s AI assistant Rovo can be hijacked through hidden text embedded in a PDF, letting an attacker turn an uploaded file into a path for data exfiltration.

PromptArmor says hidden text in PDFs can hijack Atlassian Rovo and exfiltrate data 2

The technique mirrors an older black-hat SEO trick: content that is invisible to the human reader but still readable to the system processing the page. In PromptArmor’s example, the attacker places instructions inside a document using transparent text and a 1-pixel font size.

Rovo, which works across Jira, Confluence, and other workspace tools, can then be pushed off course by a single poisoned file, according to the disclosure. A victim asks the assistant to organize tickets and uploads a document. That document contains the concealed prompt.

A person looking at the file does not see the text. The agent does. PromptArmor says the hidden instructions can tell Rovo to collect sensitive data and paste it into an attacker-controlled URL. The firm describes the issue as a zero-click attack, meaning there is no approval click and no warning during the process.

PromptArmor says hidden text in PDFs can hijack Atlassian Rovo and exfiltrate data 3

How the prompt injection works

Prompt injection happens when instructions are slipped into material an AI system is reading, causing it to follow the attacker’s directions instead of the real operator’s intent. In this case, PromptArmor is describing an indirect prompt injection attack, where the malicious instruction is stored in a file or webpage rather than typed directly into a chat prompt.

Because Rovo is designed to read content and act on it, a hidden line such as a command to send confidential tickets elsewhere can be interpreted by the model as legitimate text inside the document.

PromptArmor says disabling web search does not close the path

PromptArmor said the leak 「succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results.」 In the firm’s account, turning off the feature does not actually shut the door.

The report frames that as a serious issue because Rovo is used on top of sensitive enterprise project data and can take actions on its own. It is not described as a hobbyist tool or an isolated experiment.

PromptArmor says hidden text in PDFs can hijack Atlassian Rovo and exfiltrate data 4

Atlassian acknowledged the report, PromptArmor says

The article also points to broader testing results around AI agents. In direct tests, agents built on GPT-5 and Gemini failed to resist prompt injection more than 79% of the time. PromptArmor presents Rovo as an example of the indirect version appearing in a shipping enterprise product.

According to PromptArmor, Atlassian processed the report and thanked the company, then stopped communicating. The firm’s conclusion is that Rovo remains vulnerable.

PromptArmor wrote: 「Atlassian assigned a case number and expressed thanks, but after multiple follow-ups by PromptArmor over more than two months, Atlassian has made no further communication, and Rovo remains vulnerable.」

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
170

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.