{"slug": "hidden-text-in-a-pdf-is-enough-to-steal-sensitive-data-through-atlassian-s-ai", "title": "Hidden text in a PDF is enough to steal sensitive data through Atlassian's AI agent Rovo", "summary": "Security firm PromptArmor revealed that Atlassian's AI agent Rovo is vulnerable to an indirect prompt injection that lets attackers extract sensitive corporate data from Jira tickets and Confluence documents via a rigged PDF with hidden white-on-white text. The attack requires no user confirmation and leaves no visible traces, and Atlassian has not patched the flaw as of August 5, 2026, despite being notified on May 23, 2026.", "body_md": "# Hidden text in a PDF is enough to steal sensitive data through Atlassian's AI agent Rovo\n\n## Key Points\n\n- Security firm PromptArmor has revealed a vulnerability in Atlassian's AI agent, Rovo, that enables attackers to secretly extract sensitive corporate data from Jira and Confluence through indirect prompt injections.\n- The attack requires nothing more than a document with hidden instructions in white text. Once Rovo processes the file, the agent gathers the requested internal data and transmits it to the attacker's server via a dynamically generated URL.\n- The incident underscores that prompt injections remain an unresolved AI security problem, one that also affects other systems like Microsoft Copilot.\n\n**Atlassian's AI agent Rovo is vulnerable to an indirect prompt injection that lets attackers extract sensitive corporate data from Jira tickets and Confluence documents.**\n\nSecurity firm PromptArmor documented the flaw in a detailed analysis. The attack doesn't need user confirmation and leaves no visible traces in the chat, the security firm says.\n\nRovo is an AI agent that works across Atlassian's entire product suite, with access to Jira, Confluence, and other services connected through connectors. [According to PromptArmor](https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data-bypassing-controls), this broad access is exactly what makes the vulnerability so dangerous.\n\n## A rigged PDF is all an attacker needs\n\nThe attack starts when a user asks Rovo to organize their Jira tickets and uploads a PDF. The document looks harmless, but it hides a prompt injection in white-on-white one-point text that no human would ever spot.\n\nWhen Rovo processes the request, it searches Jira and Confluence for relevant content and gets hijacked by the hidden injection. The agent builds a URL with the collected data stuffed into query parameters, then fetches it using its built-in URL retrieval tool. Complete Jira tickets, including descriptions, assignments, priorities, and labels, end up on the attacker's server. So do Confluence documents with internal content like onboarding guides or platform architecture descriptions.\n\nThe attack isn't limited to uploaded files. Support tickets, web content, or data pulled in through third-party connectors could also serve as injection sources, PromptArmor says.\n\nTurning off web search for Rovo at the org level doesn't help either. That setting removes the search function but not the \"UrlReadTool,\" which Rovo uses to open and read URLs. Since the agent dynamically builds the target URL from the prompt injection, nothing stops it from sending sensitive data to an external server.\n\nPromptArmor also found a second exfiltration path. Rovo renders Markdown images from AI outputs, and insecure Markdown image rendering is a known vector for data theft through indirect prompt injection.\n\n## Prompt injections remain an unsolved problem for AI security\n\nPromptArmor says it reported the vulnerabilities to Atlassian on May 23, 2026. Two days later, Atlassian assigned a case number and said thanks. Despite follow-up messages on June 4 and July 29, Atlassian didn't respond. As of the publication date of August 5, Rovo is still vulnerable. PromptArmor published its findings to make users aware of the risks.\n\nAnthropic recently described [progress on browser-based prompt injections](https://the-decoder.com/opus-5-may-have-solved-browser-based-prompt-injection-the-biggest-security-flaw-haunting-ai-agents/), but those advances apply to Anthropic's own AI ecosystem, which includes extra security layers. The broader problem is likely to stick around across the industry for a while. Just recently, a similar [vulnerability affecting Word documents in Copilot](https://the-decoder.com/a-security-researcher-built-a-self-spreading-worm-that-hides-inside-word-docs-and-hijacks-microsoft-copilot/) was described.\n\n```\nAI News Without the Hype – Curated by Humans\n\n\t\t\t\t\tSubscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive \"AI Radar\" frontier report six times a year, full archive access, and access to our comment section.\t\t\t\t\n\n\t\t\t\t\tSubscribe now\n```\n\n[PromptArmor](https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data)", "url": "https://wpnews.pro/news/hidden-text-in-a-pdf-is-enough-to-steal-sensitive-data-through-atlassian-s-ai", "canonical_source": "https://the-decoder.com/hidden-text-in-a-pdf-is-enough-to-steal-sensitive-data-through-atlassians-ai-agent-rovo/", "published_at": "2026-08-10 08:46:36+00:00", "updated_at": "2026-08-10 08:48:46.667545+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-policy"], "entities": ["PromptArmor", "Atlassian", "Rovo", "Jira", "Confluence", "Microsoft Copilot", "Anthropic"], "alternates": {"html": "https://wpnews.pro/news/hidden-text-in-a-pdf-is-enough-to-steal-sensitive-data-through-atlassian-s-ai", "markdown": "https://wpnews.pro/news/hidden-text-in-a-pdf-is-enough-to-steal-sensitive-data-through-atlassian-s-ai.md", "text": "https://wpnews.pro/news/hidden-text-in-a-pdf-is-enough-to-steal-sensitive-data-through-atlassian-s-ai.txt", "jsonld": "https://wpnews.pro/news/hidden-text-in-a-pdf-is-enough-to-steal-sensitive-data-through-atlassian-s-ai.jsonld"}}