Hidden PDF Text Hijacks Atlassian Rovo to Leak Data
Atlassian’s Rovo is an enterprise AI assistant that searches and acts across Jira, Confluence and connected third-party services using the signed-in user’s existing permissions. The disclosure matters because it shows how indirect prompt injection can turn legitimate access into an exfiltration channel: instructions concealed in a PDF or other content may be treated as commands, allowing an attacker to steer the assistant without breaching the underlying permission system.
PromptArmor said on August 5, 2026, that a poisoned document could make Rovo search Jira and Confluence, append retrieved information to an attacker-controlled URL and open it, with no separate approval for the transfer. The firm notified Atlassian on May 23 and said the chain still worked when organization-level Web Search was disabled because another URL-retrieval function remained available. As of August 8, no later fix for this content-borne route had been confirmed, and no real-world exploitation was reported.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.