The security team at PromptArmor has exposed a critical design flaw in Atlassian’s Rovo AI agent that effectively turns the tool into a silent data exfiltrator. The attack leverages a classic indirect prompt injection, but with a stealthy twist: malicious instructions are embedded in PDF files as 1-point, white-on-white text. When an unsuspecting user asks Rovo to summarize a document or organize Jira tickets, the agent dutifully executes the invisible commands alongside the legitimate request.

According to PromptArmor, the mechanics of this breach are alarmingly autonomous. Once triggered, Rovo begins harvesting sensitive data from Jira and Confluence, including architectural documents and ticket assignments. It doesn't need a separate web search permission to leak this information. Instead, it exploits its internal UrlReadTool to construct dynamic URLs where the stolen data is appended as query parameters. By simply 'reading' these generated links, the agent pings an external server, successfully offloading corporate secrets without leaving a trace in the chat UI.

Even more troubling is the lack of friction. The exfiltration requires zero user confirmation and bypasses organization-level web search restrictions, as the UrlReadTool remains active by default. PromptArmor also flagged a secondary vector using insecure Markdown image rendering—a known 'zombie' vulnerability that continues to haunt AI integrations. This isn't just an Atlassian problem; it is a systemic risk for any enterprise-grade assistant, including Microsoft Copilot, that lacks deep content filtering.

PromptArmor reported these findings to Atlassian on May 23, 2026, and received a case number shortly after. However, following a series of ignored follow-ups throughout June, the firm went public with the news. As of today, Rovo remains wide open to these injections, serving as a reminder that 'convenient' AI agents often prioritize functionality over the most basic security perimeters.

AI AgentsCybersecurityAI in BusinessAI SafetyAtlassian