Key facts
- The Rovo AI assistant is vulnerable to data exfiltration.
- Security firm PromptArmor reported the vulnerability.
- The attack is described as a 'zero-click' exploit.
- Attackers can embed hidden instructions in PDF files.
- These instructions can be used to exfiltrate sensitive data.
- The exploit bypasses security measures like disabling web search.
Atlassian's Rovo AI assistant is susceptible to a security vulnerability that enables the exfiltration of sensitive data, according to security firm PromptArmor. The exploit, described as a 'zero-click' attack, involves embedding hidden instructions within PDF files that Rovo AI processes. When the AI encounters these specially crafted PDFs, it executes the embedded commands, which can be used to extract and exfiltrate data. This method bypasses existing security measures, including the disabling of web search functionality within the AI assistant. PromptArmor's findings indicate that this vulnerability leaves company data exposed and at risk of unauthorized access and leakage. The nature of the 'zero-click' attack means that users do not need to interact with the malicious PDF in any way for the exploit to be triggered, increasing its potential impact. The discovery highlights ongoing challenges in securing AI assistants that process diverse file types and external data sources.
