Atlassian Rovo AI Leaks Jira and Confluence Data via Hidden Prompt Injection
Atlassian Rovo Exfiltrates Data, Bypassing Controls

PromptArmor discovered that Atlassian's Rovo AI can be tricked into exfiltrating sensitive data, including Jira tickets and Confluence documents, through indirect prompt injection. The attack exploits Rovo's URL retrieval tool, which lacks protections against dynamically created URLs, and works even when web search is disabled. Disclosed to Atlassian in May, the issue remains unpatched after two months of follow-ups.
The attack still succeeds even when web search has been disabled organization-wide.