Rovo Leaks Jira and Confluence Data: Attack via File and Link Exposed

Rovo Leaks Jira and Confluence Data: Attack via File and Link Exposed

Atlassian's Rovo assistant can be tricked into sending Jira and Confluence data to an attacker's external server. Two independent cybersecurity firms discovered the vulnerability through different routes, but only one of them is officially closed.

PromptArmor, an AI security firm, hid malicious instructions in content that Rovo reads. The company said an uploaded file was enough to make the assistant collect internal data and send it out via a URL request without a separate approval step. This method was published on August 5, 2026, and the chain worked even with Rovo's web-search feature disabled. No information about a later fix is available.

Varonis Threat Labs placed the instructions in a link instead. Researchers found that the rovoChatPrompt URL parameter preloads attacker commands into Rovo Chat. A single click from an authenticated user forced the assistant to execute them with that user's privileges and send the results to an attacker-controlled server. Varonis named the flaw RovoBlast and disclosed it through Bugcrowd. The Bugcrowd record shows Atlassian fixed the issue server-side on July 8, 2026, and the researcher validated the fix.

Neither issue requires users to apply a patch: the link-based vulnerability is closed on Atlassian's side, and for the content-borne vector the only lever is restricting which apps and groups can use Rovo at all.

PromptArmor's attack is an indirect prompt injection: attacker-controlled text is embedded in content the assistant is asked to process, and the model treats part of that text as instructions. In the published example, a user uploads a document with a concealed injection and asks Rovo to organize their Jira tickets. The assistant searches Jira and Confluence as requested, appends what it finds to an attacker's URL and opens it, after which the attacker reads the ticket and page contents from their own server logs.

PromptArmor noted that when returning to the chat, the user sees suggested ticket updates and no sign of the exfiltration. The interaction is not cleanly described as zero-click: the victim still has to expose Rovo to the poisoned content and make a normal request. PromptArmor's narrower claim is that the exfiltration step does not require separate human-in-the-loop approval. The web-search finding matters because Atlassian offers web search as a separate organization-level setting.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate