Security firm PromptArmor disclosed that Rovo, Atlassian's AI assistant, can be manipulated into sending confidential data to third parties without human approval. Hidden instructions inside files such as PDFs are able to redirect the tool, even when web search is disabled.
How the attack works
The attack, classified by the company as 'zero-click,' occurs when a user asks Rovo to organize tasks and sends a contaminated document. The PDF contains an invisible command, written, for example, in transparent color or with a 1-pixel font. When processing the file, Rovo interprets the instruction as legitimate and collects sensitive data, sending it to a URL controlled by the attacker.
PromptArmor says the flaw persists even when an organization disables Rovo's web search. The configuration does not remove the tool for opening URLs from the results, which keeps the exfiltration channel active.
No response from Atlassian
The report was delivered to Atlassian on May 23. According to PromptArmor, the company opened a ticket, thanked them, but made no further contact after repeated follow-ups for more than two months. 'Rovo remains vulnerable,' the firm concludes.
PromptArmor also highlighted that AI agents based on GPT-5 and Gemini failed to resist prompt injection attacks in more than 79% of direct tests. The Rovo case shows the indirect version of the technique in a commercial product.


