DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Atlassian Rovo Exfiltrates Data, Bypassing Controls

Quality: 8/10 Relevance: 9/10

Summary

The article reports a vulnerability in Atlassian Rovo AI that enables zero-click data exfiltration via indirect prompt injection, bypassing organization-wide web search controls. It details how Jira tickets and Confluence documents can be exfiltrated to an attacker’s site through Rovo’s URL retrieval tool, even when web search is disabled. PromptArmor disclosed the issue to Atlassian, but remediation has not been communicated, underscoring risk to tenants and the need for prompt-hardening and monitoring.

🚀 Service construit par Johan Denoyer