AI Assistant Hijacked by Hidden Text in PDFs, Leaving Data Vulnerable
A security firm has discovered that an AI assistant used by businesses can be compromised with hidden instructions in uploaded files. PromptArmor found that the Rovo AI assistant, made by Atlassian, can be steered to exfiltrate data without human approval when a poisoned file is uploaded. This vulnerability persists even if web search functionality for Rovo is disabled.
The technique exploits how AI models process text, making it difficult to distinguish between legitimate user input and hidden instructions. An attacker can embed malicious commands in a PDF document that the model will interpret as genuine requests. For instance, an instruction written in transparent color and a font size of 1 pixel may be invisible to human eyes but still recognizable by the AI.
This type of attack is known as prompt injection, where someone inserts unauthorized instructions into content being processed by an AI system. In this case, Rovo’s job is to read documents and act on them accordingly. If a hidden line in a document instructs it to send confidential tickets to an attacker-controlled URL, the model will comply without raising any alarms.
PromptArmor notes that even if organizations disable web search for Rovo, the vulnerability remains because the tool used to open search results is still active. This means that disabling one feature does not necessarily eliminate the risk of data exfiltration.
The security firm tested several AI agents built on GPT-5 and Gemini and found that more than 79% failed to resist prompt injection in direct tests. The Rovo vulnerability demonstrates how this pattern can repeat with agents designed for reading and acting, pointing them in the wrong direction.
Atlassian received PromptArmor’s report on May 23 but has since gone silent despite multiple follow-ups from the security firm. As a result, Rovo remains vulnerable to prompt injection attacks, leaving businesses that rely on it exposed to potential data breaches.