Security firm PromptArmor discovered a vulnerability in Atlassian’s Rovo AI assistant that allows attackers to hijack the software and exfiltrate corporate data through hidden instructions embedded in PDF files. The zero-click attack exploits invisible text (transparent color, 1-pixel font) that the AI model executes as a legitimate command. It works even when an organization disables web search, because the URL-opening tool remains active. Atlassian received the report on May 23 but has not communicated a fix after more than two months, according to PromptArmor. Tests on AI agents based on GPT-5 and Gemini showed resistance to prompt injection failing in over 79% of cases.
Source: Read the original article

