Atlassian Rovo can be steered into shipping Jira and Confluence data to a third party, and two research teams found different ways to make it happen. One path is patched. The other has no confirmed fix.
PromptArmor’s version is an indirect prompt injection hiding inside content Rovo reads. A user uploads a poisoned document and asks the assistant to organize their Jira tickets. Rovo collects the results, tacks them onto an attacker’s URL, and opens it, leaving the data readable in the attacker’s server logs. The firm says the leak needs no separate approval step, and turning off Rovo’s web-search option changes nothing, because the request rides a separate URL-retrieval capability that never checks whether the destination was agent-constructed.
The second route, documented through Bugcrowd and Varonis, is a one-click attack via the rovoChatPrompt URL parameter. The proof of concept directed Rovo to find data the victim could access, embed it in the path of an attacker-controlled image URL, and fetch it. A private API key from Confluence was exfiltrated this way, and the technique also worked against Jira and data reachable through SharePoint and Outlook connectors. Atlassian closed that route on July 8.
The content-borne path remains open as far as public disclosures show. PromptArmor reported it on May 23 and published August 5 after hearing nothing further. Until Atlassian says otherwise, the practical control is limiting which apps and groups can use Rovo at all.
