Skip to content
Hacker News front page

Atlassian Rovo can exfiltrate data via prompt injection, even with web search off

Atlassian Rovo Exfiltrates Data, Bypassing Controls

PromptArmor found that Atlassian's Rovo AI agent is vulnerable to zero-click data exfiltration via indirect prompt injection. A hidden instruction in an uploaded file tricks Rovo into appending Jira tickets and Confluence docs to an attacker's URL and fetching it. The attack leaves no visible trace in the chat and works even when the org-wide web search toggle is off, because the URL retrieval tool remains active. PromptArmor reported the issue to Atlassian on May 23; after a case number and two months of silence, the vulnerability is still unpatched.

Why it matters: PromptArmor's first public disclosure of an indirect prompt injection chain against Atlassian Rovo — zero-click data exfiltration bypassing org-level controls. HKR all hit, but the attack requires a user to upload a malicious file and Atlassian hasn't responded yet, so holding...

Read the original ↗Export Markdown