Hidden PDF Text Hijacks Atlassian’s Rovo AI, Leaks Data
Security firm PromptArmor reveals a zero-click indirect prompt injection in Atlassian’s Rovo AI. Attackers hide commands in PDFs using invisible text, tricking the assistant into exfiltrating sensitive data. Despite disabling web search, the exploit works, and Atlassian has not patched it after two months.
Quick Take
PromptArmor found Rovo can be tricked into leaking data via invisible PDF text.
Attack requires no user approval, working even with web search disabled.
Atlassian acknowledged the report on May 23 but has not fixed the vulnerability.
AI agents like GPT-5 and Gemini resist prompt injection only 21% of the time.
Market Impact Analysis
NeutralThe article is about an AI assistant vulnerability, with no direct connection to cryptocurrency markets or assets; it is unlikely to affect crypto prices.
Speculation Analysis
Key Takeaways
- PromptArmor discovered a zero-click indirect prompt injection in Atlassian’s Rovo AI that uses invisible PDF text to steal data.
- The exploit requires no user approval and works even if organizations disable Rovo’s web search feature.
- Atlassian acknowledged the issue on May 23 but has not released a patch, leaving Rovo exposed after two months.
- AI agents like GPT-5 and Gemini resisted prompt injection only 21% of the time in tests, highlighting widespread vulnerability.
What Happened
Cybersecurity researchers at PromptArmor uncovered a critical vulnerability in Atlassian’s Rovo AI assistant. Attackers can embed hidden commands inside PDF documents—using transparent text or 1-pixel fonts—that Rovo interprets as legitimate instructions. Once a victim uploads such a file, the AI agent silently exfiltrates sensitive data from connected tools like Jira and Confluence to an attacker-controlled server. The attack is fully automated, requiring zero user interaction or approval. Atlassian received the report on May 23 but has not issued a fix, leaving Rovo users exposed two months later.
The Numbers
PromptArmor’s disclosure reveals that Rovo’s web search toggle fails to disable the URL-opening tool, so the leak succeeds even when web search is turned off. The attack does not need malware or system compromise—just a poisoned file upload. Recent tests show that AI agents built on cutting-edge models like GPT-5 and Gemini succumb to prompt injection 79% of the time, underlining the industry-wide challenge. With Rovo sitting atop organizations’ most sensitive project data, the exposure window is dangerously wide.
Why It Happened
The core issue is that AI models cannot distinguish between invisible and visible text. When Rovo reads a PDF, it treats all textual content equally, whether it appears on screen or not. This mirrors old-school SEO tricks like white-on-white keyword stuffing. Attackers exploit this blind spot by planting instructions that the model obeys, because it sees them as part of the user’s request. Indirect prompt injection thrives when agents have read-and-act capabilities without adequate content sanitization. Atlassian’s slow response highlights a gap in security maturity for enterprise AI tools.
Broader Impact
This incident is not isolated. As AI agents gain access to more enterprise systems, the attack surface for prompt injection expands. The same vulnerability class affects agents from major labs, as shown by the 79% failure rate. Companies relying on AI copilots must re-evaluate how these tools handle untrusted content. The Rovo case could serve as a wake-up call for stricter defenses against indirect injection, especially in products handling sensitive corporate data.
What to Watch Next
- Atlassian’s next move: Whether a patch arrives soon or the company provides a timeline—prolonged silence could erode trust.
- Industry response: Adoption of input sanitization standards and AI agent safeguards may accelerate after this disclosure.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.