Atlassian Rovo Exfiltrates Data, Bypassing Controls

Security researchers have identified a vulnerability in Atlassian's Rovo AI that allows attackers to exfiltrate sensitive data via indirect prompt injection. Despite disclosure, the issue remains unpatched, prompting a public warning to users of Jira and Confluence.
Why it matters
This highlights the critical security risks associated with integrating AI agents into enterprise software suites without robust data controls.
Atlassian Rovo AI exfiltrates data, bypassing controls: attacker logs contain Jira tickets and Confluence docs. Context Atlassian’s Rovo AI is a multi-purpose agent that operates across Atlassian’s product suite (Jira, Confluence, etc.).
Vulnerabilities have been identified that enable data exfiltration across an Atlassian tenant (Jira tickets, Confluence docs, etc.) via indirect prompt injection. This attack executes without requiring any human-in-the-loop approval, and succeeds by exploiting Rovo's URL retrieval tool.
The attack still succeeds even when web search has been disabled organization-wide.
PromptArmor disclosed the vulnerabilities covered in this article to Atlassian on May 23rd. Atlassian assigned a case number and expressed thanks, but after multiple follow-ups by PromptArmor over more than two months, Atlassian has made no further communication, and Rovo remains vulnerable. As such, we are publishing to inform users of the risks.
The victim prepares a query asking Rovo to organize Jira tickets
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in