The Rovo AI assistant, developed by Atlassian, is susceptible to data exfiltration through a 'zero-click' attack that exploits hidden instructions within PDF files, according to security firm PromptArmor. This indirect prompt injection technique allows malicious commands to be embedded in documents that Rovo processes, directing it to send sensitive company data to an attacker-controlled URL. The vulnerability persists even when Rovo's web search feature is disabled, as the underlying tool for opening URLs remains active. PromptArmor reported the issue to Atlassian on May 23, but after two months and multiple follow-ups, the company states Rovo remains vulnerable. This exploit highlights a broader trend where AI agents, which often operate with significant access to company data and the ability to act autonomously, are vulnerable to prompt injection, with tests showing over 79% of AI agents failing to resist such attacks.