HackMyIP
← Back to News
2026-08-08 The Hacker News

Atlassian Rovo Prompt Injection Flaws Expose Jira and Confluence Data

AI SecurityLLM SecurityVulnerability

Two independent security firms have uncovered prompt injection vulnerabilities in Atlassian's Rovo AI assistant that could allow attackers to harvest sensitive Jira and Confluence data from any signed-in user's account and exfiltrate it to an external server. The findings, disclosed within days of each other, highlight how enterprise AI agents that read internal content on a user's behalf create new data-leak surfaces beyond traditional application security boundaries.

Varonis Threat Labs traced one chain to the `rovoChatPrompt` URL parameter, which preloads attacker-controlled instructions into Rovo Chat. A single click from an authenticated user is enough for Rovo to execute the injected directives under that user's permissions and forward the results to an attacker-controlled endpoint. Varonis named the flaw RovoBlast and disclosed it through Bugcrowd; the Bugcrowd record confirms Atlassian patched it server-side on July 8, 2026, with the reporter validating the fix. No customer-side action is required for this particular issue.

PromptArmor took a different route via indirect prompt injection through uploaded content. In the firm's published example, a user uploads a document containing hidden instructions and asks Rovo to organize their Jira tickets. Rovo searches Jira and Confluence as requested, appends the findings to an attacker-supplied URL, and opens it. The attacker then reads the ticket metadata and page contents from their own server logs, while the victim sees only the suggested ticket updates and no trace of the exfiltration step. PromptArmor reported on August 5, 2026, that the chain still functions with Rovo's web-search setting disabled, because the outbound call uses a separate URL-retrieval capability. The root cause, the firm notes, is that nothing checks whether an agent-constructed URL was intended by the user; Rovo's rendering of Markdown images from model output provides a second exfiltration channel that was documented but not fully chained in the report. Unlike the Varonis finding, the content-borne path is single-sourced and the article does not confirm a remediation at publication, leaving administrators to scope which apps and groups can use Rovo at all as the primary mitigation. Organizations evaluating their exposure to AI-assisted data flows can audit outbound traffic with a DNS leak test to detect unexpected external resolutions, while security teams should also review identity hygiene via a password checker and monitor for compromised credentials linked to Atlassian accounts with a email breach checker.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →