Hidden text in a PDF is enough to steal sensitive data through Atlassian's AI agent Rovo
Security researchers at PromptArmor discovered that malicious instructions hidden within a PDF can hijack Atlassian's AI agent Rovo to exfiltrate sensitive data from Jira and Confluence. Because the process executes silently without requiring user authorization or leaving a record of the breach, it poses a significant risk to organizations that use the tool to index internal documents. This vulnerability highlights the security challenges associated with granting AI agents autonomous access to sensitive enterprise databases.
Covered by 1 source
- TThe Decoder↗Matthias BastianAug 10