Summary
- According to PromptArmor, the Rovo AI assistant can be manipulated to extract data without user consent through concealed commands embedded in uploaded files, such as PDFs.
- This method is effective even if Rovo's web search feature is disabled, as the tool for opening URLs remains functional.
- Atlassian, the developer behind Rovo, received the security report on May 23, but two months later, Rovo still has not been patched and remains vulnerable, as stated by PromptArmor.
The practice of embedding invisible keywords in web pages to deceive search engines is resurfacing, now targeting AI models. Attackers can embed covert instructions within a PDF that the AI cannot differentiate from legitimate user input, prompting it to act accordingly.
As detailed by PromptArmor, Rovo—Atlassian's assistant integrating with tools like Jira and Confluence—can be exploited as a data conduit by simply uploading a compromised file. For instance, when a user requests Rovo to organize tickets and uploads a document containing a hidden prompt (such as text in a transparent color with a font size of one pixel), the AI inadvertently follows the malicious directive.
Although invisible to the human eye, the AI recognizes the cloaked instruction as valid text within the document. This can lead Rovo to collect sensitive information and transmit it to a URL controlled by an attacker, an approach identified as a zero-click attack, since it bypasses the need for user approval or alerts.
Rovo AI assistant hijacked. Image: PromptArmorPrompt injection refers to the act of embedding commands within the content an AI processes, effectively taking control away from its intended user. The term "indirect" signifies that the harmful instruction exists within a file or web page rather than directly in a conversation. Since Rovo's purpose is to process and act upon information, a concealed command like "send the confidential tickets here" is interpreted by the AI as a legitimate request.
PromptArmor notes that this data leak is effective even if an organization has turned off Rovo's web search capability. The setting does not eliminate the functionality for opening search results, thus leaving a vulnerability intact.
Rovo AI assistant hijacked. Image: PromptArmorRovo is not a simple tool; it operates over a company's critical project data autonomously. In tests, AI agents built on GPT-5 and Gemini have failed to defend against prompt injection attacks over 79% of the time, with Rovo exemplifying how indirect attacks can infiltrate commercial products. This pattern of AI agents being misdirected continues to emerge.
After receiving the report, Atlassian acknowledged PromptArmor's findings but has since ceased communication. PromptArmor concludes that Rovo "remains vulnerable." "Atlassian acknowledged the report and assigned a case number, but after numerous follow-ups from PromptArmor over the span of two months, there has been no further response from Atlassian, and Rovo still has not been secured," the firm stated.
