Atlassian's AI agent Rovo is vulnerable to an indirect prompt injection that lets attackers extract sensitive corporate data from Jira tickets and Confluence documents.

Security firm PromptArmor documented the flaw in a detailed analysis. The attack doesn't need user confirmation and leaves no visible traces in the chat, the security firm says.

Rovo is an AI agent that works across Atlassian's entire product suite, with access to Jira, Confluence, and other services connected through connectors. According to PromptArmor, this broad access is exactly what makes the vulnerability so dangerous.

A rigged PDF is all an attacker needs

The attack starts when a user asks Rovo to organize their Jira tickets and uploads a PDF. The document looks harmless, but it hides a prompt injection in white-on-white one-point text that no human would ever spot.