Invisible One-Point Text in a PDF Can Siphon Jira Data Out Through Atlassian’s Rovo
Security firm PromptArmor has detailed a vulnerability in Atlassian's AI agent, Rovo, allowing for data exfiltration from Jira and Confluence through specially crafted PDFs. The attack uses invisible, one-point text within a PDF to inject commands that cause Rovo to fetch and send sensitive ticket and document data to an attacker-controlled URL. PromptArmor reported the vulnerability to Atlassian in May 2026 but received no response, leading to public disclosure.
EGamers.io
Original source
This article was reported and published by EGamers.io. feed.gg links to it as part of a story cluster — full text, images and rights remain with the publisher.