Atlassian Rovo Exfiltrates Data, Bypassing Controls
Summary
The article reports a vulnerability in Atlassian Rovo AI that enables zero-click data exfiltration via indirect prompt injection, bypassing organization-wide web search controls. It details how Jira tickets and Confluence documents can be exfiltrated to an attacker’s site through Rovo’s URL retrieval tool, even when web search is disabled. PromptArmor disclosed the issue to Atlassian, but remediation has not been communicated, underscoring risk to tenants and the need for prompt-hardening and monitoring.