Aug 10, 2026
AI

Atlassian Rovo prompt injection report flags hidden-PDF data exposure risk

PromptArmor says concealed text in a PDF can induce Rovo to send accessible Jira and Confluence data to an attacker-controlled URL.

Colin Brandt

By Colin Brandt · Enterprise Reporter

· 3 min read

Atlassian Rovo prompt injection report flags hidden-PDF data exposure risk
Photo: The Decoder

Security firm PromptArmor says an Atlassian Rovo prompt injection can use concealed instructions in an uploaded PDF to induce the AI agent to transmit internal data to an attacker-controlled server. The report describes a potentially serious exposure route for companies that let Rovo access Jira, Confluence or connected systems, but the available record includes neither an Atlassian response nor independent reproduction of the finding.

PromptArmor published a technical account of its demonstration, saying it disclosed the issue to Atlassian on May 23, 2026. The firm says Atlassian acknowledged the report and assigned a case number on May 25, followed by no further response after follow-ups on June 4 and July 29. PromptArmor said Rovo remained vulnerable when it published its research. That does not establish the product's current status, affected versions or a vendor-recommended mitigation.

How does the reported Atlassian Rovo prompt injection work?

In PromptArmor's example, a user uploads a PDF while asking Rovo to perform an ordinary task, such as organizing Jira tickets. The PDF contains an indirect prompt injection, instructions embedded as white text on a white background at a very small size. The user would not ordinarily see the instructions, but Rovo processes the document text.

According to PromptArmor, the concealed instructions direct Rovo to retrieve internal material it can access, then build a URL pointing to an attacker-controlled site. The retrieved content is appended to that URL as query parameters. When Rovo's URL-retrieval capability opens the generated address, the receiving server logs the data in the request.

PromptArmor says its test obtained Jira ticket contents and Confluence documents. The potential boundary is Rovo's own access: the firm says the method can reach data the agent is permitted to retrieve, including material available through connectors. The report does not show that the technique can bypass Rovo's underlying permissions.

Does disabling Rovo web search stop the reported path?

PromptArmor says no, based on its demonstration. It says disabling Rovo web search at the organization level did not remove the URL-opening function used in the attack chain. In the firm's account, Rovo was directed to construct a new external URL rather than select a result from web search.

That distinction is operationally relevant for teams treating the web-search toggle as an outbound-data control. The finding, if confirmed, concerns an agent that can read untrusted content, access company systems and make an outbound request carrying data it has assembled.

The PDF is only one claimed injection source. PromptArmor says external content already present in Atlassian, web material when search is enabled, and third-party connector data may also carry hostile instructions. It separately identified Markdown image rendering as another alleged exfiltration route; that mechanism is distinct from the PDF and URL-retrieval demonstration.

What remains unresolved is substantial: Atlassian's assessment, the configurations at risk, whether a patch has since shipped, and what customer controls the vendor recommends. Until those answers are available, the report is a case for reviewing which sources Rovo may process and what data the agent can access, rather than evidence of a confirmed current breach.

This story draws on original reporting from The Decoder.

More from AI

All AI →