EGEGamers.io
Invisible One-Point Text in a PDF Can Siphon Jira Data Out Through Atlassian’s Rovo
Security firm PromptArmor has detailed a vulnerability in Atlassian's AI agent, Rovo, allowing for data exfiltration from Jira and Confluence through specially crafted PDFs. The attack uses invisible, one-point text within a PDF to inject commands that cause Rovo to fetch and send sensitive ticket and document data to an attacker-controlled URL. PromptArmor reported the vulnerability to Atlassian in May 2026 but received no response, leading to public disclosure.