
Hidden PDF text turns Atlassian's Rovo agent into a Jira and Confluence leak
PromptArmor showed that white-on-white one-point text in an uploaded PDF hijacks Atlassian's Rovo agent, which then packs Jira tickets and Confluence documents into URL query parameters and fetches them to an attacker's server, with no user confirmation and no visible trace in the chat. Turning off web search at the org level does not close it — Rovo's separate URL-reading tool still opens the dynamically built link, and Markdown image rendering gives a second exfiltration path. Atlassian assigned a case number on 25 May 2026 and then went silent through two follow-ups; Rovo was still unpatched when PromptArmor published on 5 August.
Source: the-decoder.com ↗
A rigged PDF is all an attacker needs
PromptArmor
Why this matters
- → One hidden-text PDF hijacks AI agents to steal Jira tickets and Confluence docs
- → No user confirmation, no chat trace—exfiltration happens invisibly
- → Org-level security controls (disabling web search) don't block the leak
Invisible ink, real breach