返回全部动态

Atlassian AI 代理 Rovo 遭提示注入漏洞,可窃取企业敏感数据

原标题:Hidden text in a PDF is enough to steal sensitive data through Atlassian's AI agent Rovo

THE DECODER安全质量 75

AI 摘要

安全公司 PromptArmor 披露,Atlassian 的 AI 代理 Rovo 存在间接提示注入漏洞,攻击者可通过在 PDF 中隐藏白色文本指令,在无需用户确认的情况下窃取 Jira 和 Confluence 中的敏感数据。该漏洞利用 Rovo 的 URL 读取工具和 Markdown 图像渲染功能,将数据外传至攻击者服务器。PromptArmor 于 2026 年 5 月报告漏洞,但 Atlassian 未修复,截至 8 月 5 日仍受影响。此事件凸显提示注入仍是 AI 安全领域的未解问题,类似漏洞也影响微软 Copilot。

以上摘要由 AI 生成,可能存在误差。事实请以原文为准。

正文节选

Hidden text in a PDF is enough to steal sensitive data through Atlassian's AI agent Rovo Key Points - Security firm PromptArmor has revealed a vulnerability in Atlassian's AI agent, Rovo, that enables attackers to secretly extract sensitive corporate data from Jira and Confluence through indirect prompt injections. - The attack requires nothing more than a document with hidden instructions in white text. Once Rovo processes the file, the agent gathers the requested internal data and transmits it


发布时间:2026-08-10 16:46
抓取时间:2026-08-10 17:44
来源机构:THE DECODER
阅读原文the-decoder.com