Atlassian's AI assistant Rovo has been claimed to be capable of sending Jira tickets and Confluence documents externally due to hidden instructions in PDFs. Security firm PromptArmor stated that if a user uploads a PDF containing hidden phrases to Rovo, the assistant may recognize these as commands and transmit information to an attacker's URL. This attack method is known as a 'zero-click attack', where attackers insert transparent text or 1-pixel sized phrases into the PDF to prevent users from noticing them. When users delegate tasks to Rovo, the AI can execute the hidden instructions. PromptArmor argued that even if Rovo's web search function is turned off, tools for opening URLs remain, thus maintaining the information leakage pathway. Atlassian explained that Rovo can reference files uploaded by users in a work context and can read formats such as PDF, DOC, JSON, CSV, and PPT. However, there is also a possibility that external content could influence the AI's behavior, and malicious instructions hidden in documents could lead the AI to perform unintended actions. PromptArmor classified this as 'indirect prompt injection' and reported that discussions regarding this issue are ongoing within the Atlassian community. So far, Atlassian has not issued any official patch notices or acknowledged the vulnerability.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























