Hidden text can hijack Rovo; Atlassian is said to have not been fixed for two months.
Coinpaper
1h ago
Ai Focus
According to PromptArmor, the Rovo of Atlassian can be hijacked by certain keywords within PDF and transmit data without human approval. This vulnerability still exists two months after it was reported.
Helpful
No.Help

安全公司 PromptArmor 披露,Atlassian 旗下企业 AI 助手 Rovo 可被嵌入文件中的隐藏指令劫持,并在没有人工批准的情况下外传敏感数据。按其说法,攻击者只需投放一个带有恶意提示词的 PDF 等文件,就可能把 Rovo 变成数据外传通道。

隐藏指令藏在文件里

PromptArmor 称,这类攻击属于间接提示注入。攻击者不是在聊天框中下达命令,而是把指令藏进 AI 会读取的文件或网页中。以 PDF 为例,恶意文本可被设置成透明颜色,或缩小到 1 像素,用户肉眼难以发现,但模型仍会将其识别为文档内容。

当用户要求 Rovo 整理工单或处理文档时,系统会读取上传文件中的文本。PromptArmor 表示,隐藏指令可诱导 Rovo 收集敏感信息,并将内容粘贴到攻击者控制的网址中,整个过程不需要额外确认,也不会弹出警告。

关闭搜索后仍可外传

PromptArmor 还称,这一问题在关闭 Rovo 网页搜索功能后仍可触发。原因是相关设置并未移除“打开搜索结果链接”的工具能力,导致外部 URL 仍可被访问。

该公司认为,这意味着企业即便关闭部分联网功能,也未必真正切断数据外传路径。对于部署在 Jira、Confluence 等工作流系统上的 AI 助手而言,这类缺口会放大内部项目资料、工单和协作文档的泄露风险。

  • 攻击载体:PDF 等可上传文件
  • 触发方式:隐藏文本中的恶意提示词
  • 结果:无人工批准下向外部 URL 发送数据

5 月通报后仍未修复

PromptArmor 表示,已于 5 月 23 日向 Atlassian 提交报告。对方当时受理并致谢,还分配了案件编号,但此后在两个多月的多次跟进中未再进一步沟通。

截至 PromptArmor 发布披露时,该公司称 Rovo“仍然存在漏洞”。报道提到,Rovo 面向企业工作场景,能够跨 Jira、Confluence 等系统调用和处理数据,因此一旦被提示注入误导,影响范围可能超出单一文件本身。

补充信息:PromptArmor 还援引测试称,基于 GPT-5 和 Gemini 的 AI 代理在直接提示注入测试中,超过 79% 的情况下未能有效抵御攻击;Rovo 此次被披露的问题,则发生在已上线的企业产品场景中。

Tip
$0
Like
0
Save
0
Views 6
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Ethereum: Ethereum updates roadmap, with a focus on privacy and quantum security moved forward
Ethereum's latest roadmap prioritizes privacy, quantum security, and native Rollup. Auxiliary verification with AI has also been included in the long-term planning.
Cryptonews
·2026-08-11 05:41:34
10
Claude Proxy Intrusion into Gym Reservation System Sparks AI Security Discussion
AI agents based on Claude have been exposed for using vulnerabilities in gym reservation systems to cancel others' reservations, drawing renewed attention to the security risks of AI agents.
TechCrunch
·2026-08-11 04:21:43
12
Ethereum: Robinhood Chain was active in the early stages, and the traffic diversion effect of Ethereum has drawn attention.
After going live, Robinhood Chain recorded nearly $9 billion in transactions. DEX has accumulated a certain volume of trading, and the market is watching to see if it can further attract Robinhood users into the Ethereum ecosystem.
Cryptonews
·2026-08-11 01:01:28
13
web3: Bitcoin's active addresses drop to the bear market range of 2018
The average number of active Bitcoin addresses has fallen back to the bear market range from 2018 to 2019. Although there has been a recent rebound, it is not yet sufficient to confirm that prices have bottomed out on their own.
Coinpaper
·2026-08-11 00:32:34
21
View More