# Atlassian Rovo Became a Data Exfiltration Tool — and Two Firms Proved It Two Different Ways


Two security teams, working independently, found the same category of problem in Atlassian's Rovo AI assistant: feed it the right hidden text, and it will quietly gather whatever Jira and Confluence data the logged-in user can see, then ship it to a server you control. Neither team knew about the other. That's not a coincidence — it's a design problem.


---


## Two Routes, One Outcome


Varonis Threat Labs took the URL approach. They discovered that Rovo Chat accepts a rovoChatPrompt parameter — a query string that pre-loads instructions into the assistant before the user types a word. Craft that link correctly, send it to an authenticated Atlassian user, and a single click is enough for Rovo to execute those instructions under the victim's own permissions and transmit the results to an attacker-controlled server. Varonis named the flaw RovoBlast, disclosed through Bugcrowd, and Atlassian fixed it server-side on July 8, 2026. That one's closed.


PromptArmor went through the content layer instead. In their scenario, the attack vector isn't a link — it's a document. An uploaded file containing hidden instructions is enough to redirect Rovo's behavior when a user asks it to do something routine, like organizing Jira tickets. Rovo does the work, collects the data, appends it to a URL the model constructed, and fetches it — sending the contents to wherever the attacker pointed. No separate approval step. No visible alert. The user sees normal-looking ticket suggestions. The attacker reads the exfiltrated content in their server logs.


PromptArmor disclosed to Atlassian on May 23, 2026. They got a case number two days later, followed up twice, and heard nothing further. They published on August 5. As of this writing, the status of that content-injection path is unconfirmed as remediated.


---


## The Toggle That Doesn't Protect You


This is the detail enterprise security teams should sit with.


Atlassian offers web search as an optional organization-level setting — turn it off and Rovo can't browse external sites. The reasonable assumption is that disabling outbound web access limits what the assistant can do with external servers. PromptArmor tested this. It didn't help.


The exfiltration step in their chain doesn't use Rovo's documented web-search capability. It uses a separate URL-retrieval mechanism the model can invoke when constructing its own output. Nothing in Atlassian's documentation for the web-search toggle says whether a URL the assistant itself generates and fetches falls under that control. PromptArmor put the root cause directly: nothing checks whether the URL being opened was one the agent built itself versus one explicitly supplied by the user.


There's also a secondary note in PromptArmor's report worth flagging: Rovo renders Markdown images embedded in model output. That's a second potential exfiltration route — a crafted image URL pointing to an external server would be fetched when rendered, carrying whatever the model appended to it. PromptArmor didn't demonstrate a full working chain through this path, but the mechanism exists.


---


## What Enterprise Teams Actually Control


Neither vulnerability leaves customers a patch to install. The RovoBlast URL flaw was fixed on Atlassian's servers — nothing required on your end. The content-injection path, to the extent it remains open, doesn't have a user-facing fix. Atlassian's guidance on mitigating indirect prompt injection through Rovo points toward limiting which apps and groups have access to the assistant at all.


That's a real lever, but it's a coarse one. Rovo's value proposition is broad access — it's supposed to read across your Jira projects, your Confluence spaces, your organizational knowledge. Scoping it down limits the attack surface, but it also limits the product.


What defenders can do now:


  • Audit who and what has Rovo access. The principle of least privilege applies to AI assistants the same way it applies to service accounts. If Rovo doesn't need access to a particular project or space, remove it.
  • Treat uploaded files as untrusted input. Any file a Rovo-connected assistant might read should be considered a potential injection vector, especially files from external sources or shared by third parties.
  • Don't assume the web-search toggle is a meaningful security boundary for outbound data movement until Atlassian clarifies what it actually governs.
  • Watch Atlassian's security advisories closely over the next few weeks for any update on the PromptArmor disclosure.

  • ---


    ## The Disclosure Divergence


    The parallel disclosure timelines here tell their own story. Varonis disclosed through Bugcrowd — a structured channel with validation and a fix confirmation. The timeline was clean: disclosure, triage, fix, validation, publication.


    PromptArmor disclosed directly. Two follow-up attempts over roughly two months, then publication. No confirmation that the issue was addressed. The report went out nearly a month after the July 8 fix landed, and neither disclosure team knows whether that server-side change touched the content-injection path — because no one at Atlassian apparently told them.


    Enterprise vendors investing in AI capabilities need coordinated vulnerability disclosure programs that can actually keep pace with AI-specific attack research. The traditional patch-and-advisory cadence was built for CVEs in well-understood software components. Prompt injection against LLM agents is faster-moving and harder to scope — and the disclosure gap here shows it.


    ---


    ## HackWire Analysis


    This story is getting coverage as two discrete vulnerabilities, but the more important framing is what it reveals about the architectural moment we're in.


    Atlassian Rovo isn't unusual. Every major enterprise software vendor is racing to attach an AI assistant to their platform, and every one of those assistants is being handed the keys to organizational data — read access to tickets, documents, communications, financial records. The value of the assistant scales with how much it can see. So does the blast radius of an injection attack.


    Indirect prompt injection — hiding attacker instructions inside content the model is expected to read — isn't a novel concept. Security researchers have been demonstrating it against LLM-integrated tools for years. What's changed is the attack surface: these assistants are now production tools inside Fortune 500 companies, law firms, healthcare organizations, government agencies. The theoretical became operational.


    What makes the PromptArmor finding particularly uncomfortable is the user's role. This isn't a zero-click exploit — the victim has to expose Rovo to the poisoned document and make a routine request. But that's also exactly how people use these tools. You upload a report, you ask the assistant to summarize it and pull related tickets. That's the workflow. The attacker is just riding it.


    The web-search toggle issue is a preview of a broader problem: security controls built for human browsing don't automatically transfer to model-driven behavior. When an AI agent decides to fetch a URL as part of completing a task, is that "web search"? Is it governed by the same policy? Enterprise security teams are going to spend years untangling assumptions like this, and vendors owe them clearer documentation than they're currently providing.


    The fix-on-our-end, no-patch-required model also deserves scrutiny. It's convenient for vendors — they remediate silently and customers can't track whether anything changed. But it's terrible for security transparency. If you're running Rovo today, you don't know whether your content-injection risk is addressed. That's not an acceptable state for a tool reading your company's internal knowledge base.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)