
Atlassian's Rovo AI Agent Leaks Jira and Confluence Data via Hidden PDF Text
Security firm PromptArmor disclosed a vulnerability in Atlassian's AI agent Rovo that allows attackers to steal sensitive data from Jira and Confluence via hidden white-on-white text in PDFs. The indirect prompt injection attack requires no user confirmation and leaves no visible traces. Atlassian has not responded to the disclosure, leaving the vulnerability unfixed as of August 2026.
