All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Rovo AI Assistant Vulnerable to Data Exfiltration via Hidden PDF Instructions

Created at 10 Aug · 8:00 PM1 source↑ Market-relevant
IN SHORT

Security firm PromptArmor reports that Atlassian's Rovo AI assistant can be exploited to exfiltrate sensitive data through hidden instructions embedded in PDF files. This 'zero-click' attack bypasses security measures like disabling web search, leaving company data at risk.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

79%AI agents failed to resist prompt injection
May 23Date Atlassian received the report
two monthsTime since Atlassian's last communication

Who's Involved

PromptArmor
Security company that disclosed the Rovo AI vulnerability
Rovo
Atlassian's AI assistant for Jira and Confluence
Atlassian
Maker of the Rovo AI assistant
Rovo AI Assistant Vulnerable to Data Exfiltration via Hidden PDF Instructions

↳ Why This Matters

This vulnerability poses a significant risk to businesses using AI assistants like Rovo, as sensitive company data could be leaked without any user interaction or awareness, potentially leading to data breaches and operational disruption.

Key facts

  • Rovo AI assistant can be manipulated to exfiltrate data through hidden instructions in PDF files.
  • The vulnerability is a 'zero-click' attack, requiring no user approval.
  • The exploit remains effective even if Rovo's web search functionality is disabled.
  • Atlassian was notified of the vulnerability over two months ago and has not yet addressed it.
  • Prompt injection attacks hijack AI models by embedding malicious commands within content they process.
  • The Rovo AI assistant, developed by Atlassian, is susceptible to data exfiltration through a 'zero-click' attack that exploits hidden instructions within PDF files, according to security firm PromptArmor. This indirect prompt injection technique allows malicious commands to be embedded in documents that Rovo processes, directing it to send sensitive company data to an attacker-controlled URL. The vulnerability persists even when Rovo's web search feature is disabled, as the underlying tool for opening URLs remains active. PromptArmor reported the issue to Atlassian on May 23, but after two months and multiple follow-ups, the company states Rovo remains vulnerable. This exploit highlights a broader trend where AI agents, which often operate with significant access to company data and the ability to act autonomously, are vulnerable to prompt injection, with tests showing over 79% of AI agents failing to resist such attacks.

    Frequently asked questions

    Rovo is an AI assistant developed by Atlassian that integrates with tools like Jira and Confluence to help organize and manage project data within a company's workspace.

    Attackers embed hidden instructions within PDF files. When a user asks Rovo to process such a file, the AI interprets these hidden instructions as commands, leading it to exfiltrate data to an attacker-controlled URL.

    This is an example of 'indirect prompt injection,' where malicious instructions are placed in content an AI reads, rather than directly in the chat interface. It's a form of prompt injection, a known vulnerability in AI systems.

    A zero-click attack requires no action from the victim beyond the initial exposure to the malicious element, such as uploading a poisoned file. There is no need for the user to click a link or approve an action.

    What Happens Next

    01Atlassian is expected to address the reported vulnerability in Rovo.
    02Further research into AI agent security and prompt injection defenses is anticipated.

    Get the newsletter.

    Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

    Cadence

    How It Developed

    PromptArmor discovered Rovo AI assistant can be steered to exfiltrate data via hidden instructions in uploaded files.
    The vulnerability persists even when Rovo's web search is disabled, as its URL-opening tool remains active.
    Atlassian received the report on May 23 but has not addressed the vulnerability in the two months since.
    Prompt injection attacks involve embedding instructions within content an AI reads, hijacking its function.
    Indirect prompt injection, as seen with Rovo, places malicious instructions in files or webpages rather than the chat interface.
    The attack allows sensitive data to be sent to an attacker-controlled URL without user approval or warning.
    AI agents, including those built on GPT-4 and Gemini, have shown a high susceptibility to prompt injection.
    PromptArmor states Rovo remains vulnerable after Atlassian failed to communicate further on the issue for over two months.

    Sources

    T1
    Hidden Text in PDFs Is Hijacking This AI AssistantDecrypt

    Related Stories

    AI agent hacks gym reservation system, highlighting security vulnerabilities
    10 Aug · 8:16 PM
    US House Democrats demand answers on rogue AI agents from OpenAI, Anthropic
    10 Aug · 4:06 PM
    Researcher's "noreply" domains reveal corporate data leaks
    10 Aug · 2:31 PM
    OpenAI Pauses Development of 'Astra' AI Model Over Cyber Risk Concerns
    10 Aug · 3:11 PM
    Klaviyo data leak: Passwords shared with advertisers due to website bug
    10 Aug · 2:36 PM