Invisible ink, visible exfil: poisoned PDFs turn Atlassian's Rovo into a prompt-injection straw 📄
A single PDF can turn Atlassian's Rovo AI agent into an unauthorized data pipeline, according to a disclosure from security firm PromptArmor. The technique, a variant of white-text-on-white-background search engine manipulation repurposed for large language models, embeds instructions in transparent, 1-pixel font that human readers cannot see but an agent treats as legitimate commands. PromptArmor described the attack as zero-click: no approval prompt and no warning is shown to the user, and exfiltration succeeds even when web search is disabled, because the setting does not remove the tool used to open search results.
In the disclosed scenario, a victim asks Rovo to organize tickets and uploads a document that carries a hidden prompt instructing the agent to gather sensitive data and post it to an attacker-controlled URL. Rovo is designed to read content across Jira, Confluence, the rest of the Atlassian workspace and act on it, which makes embedded instructions functionally indistinguishable from a user's request. "Indirect" prompt injection refers to the poison living in a file or webpage rather than typed into the chat box; a "direct" injection is delivered in the chat itself. PromptArmor said the leak "succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results."
The disclosure lands as separate testing has shown AI agents are highly susceptible to the same class of attack. PromptArmor cited an assessment in which agents built on GPT-5 and Gemini failed to resist prompt injection more than 79% of the time in direct tests, and Rovo, the firm wrote, demonstrates the indirect variant arriving in a shipping enterprise product. The pattern, the researchers said, keeps repeating with agents that can read and act being pointed the wrong way.
PromptArmor reported the issue to Atlassian, which assigned a case number and thanked the firm, but did not provide further updates. "Atlassian assigned a case number and expressed thanks, but after multiple follow-ups by PromptArmor over more than two months, Atlassian has made no further communication, and Rovo remains vulnerable," PromptArmor wrote. GasCope has reached out to Atlassian for comment.
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.