Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Security Researchers Expose Critical Vulnerability in Atlassian's Rovo AI Assistant Allowing Data Exfiltration
00

Security Researchers Expose Critical Vulnerability in Atlassian's Rovo AI Assistant Allowing Data Exfiltration

Aug 8, 2026

Security researchers have exposed critical prompt injection vulnerabilities in Atlassian's Rovo AI assistant that allow silent data exfiltration from Jira and Confluence. PromptArmor revealed that attackers can hide invisible commands in uploaded PDFs to force Rovo to transmit sensitive data to external servers. Although Atlassian patched a separate vulnerability reported by Varonis on July 8, 2026, the firm has not patched PromptArmor's May 23 disclosure, leaving Rovo actively vulnerable.

Rovo prompt injection vulnerabilities

  • ▪Security firm PromptArmor discovered a zero-click indirect prompt injection vulnerability in Atlassian's Rovo AI assistant that allows data exfiltration without human approval.
  • ▪Varonis Threat Labs identified a separate prompt injection vulnerability in Atlassian's Rovo AI assistant, dubbed RovoBlast, which exploits a URL parameter named rovoChatPrompt.

Hidden text attack vectors

  • ▪PromptArmor reported that support tickets, web content, or data pulled through third-party connectors can also serve as injection sources to hijack Atlassian's Rovo AI assistant.
  • ▪Attackers can hijack Atlassian's Rovo AI assistant by embedding invisible commands, such as white-on-white text in a one-point font, inside uploaded files like PDFs.

URL-based data exfiltration

  • ▪Atlassian's Rovo AI assistant renders Markdown images from AI outputs, which PromptArmor identified as a second exfiltration path for data theft.
  • ▪The prompt injection vulnerability in Atlassian's Rovo AI assistant exploits its built-in URL retrieval tool, or UrlReadTool, to transmit gathered data to an attacker-controlled server.
  • ▪Disabling the web search feature for Atlassian's Rovo AI assistant fails to block data exfiltration because the underlying UrlReadTool remains active.

Jira Confluence data exposure

  • ▪The Varonis-discovered RovoBlast vulnerability allows Atlassian's Rovo ResearchAgent tool to autonomously pull data from integrated services including SharePoint, Slack, Google Workspace, and Microsoft 365.
  • ▪The prompt injection vulnerabilities in Atlassian's Rovo AI assistant can expose sensitive corporate data, including Jira ticket contents, Confluence page text, private API keys, and workspace member lists.

Atlassian disclosure response timeline

  • ▪Atlassian assigned a case number and thanked PromptArmor on May 25, 2026, but failed to communicate further despite follow-ups on June 4, 2026, and July 29, 2026.
  • ▪Atlassian shipped a server-side fix for the Varonis-reported RovoBlast vulnerability on July 8, 2026, through its Bugcrowd bug bounty program.
  • ▪PromptArmor privately disclosed its discovered vulnerability to Atlassian on May 23, 2026, and published details publicly on August 5, 2026, after Atlassian went silent and left the flaw unpatched.

AI agent security weaknesses

  • ▪Security researchers have identified similar indirect prompt injection vulnerabilities in other enterprise AI tools, including a recent flaw affecting Word documents in Microsoft Copilot.
  • ▪Indirect prompt injection is a structural weakness affecting AI assistants that process untrusted external content while holding privileged access to internal systems.

4 sources

Egamers
Invisible One-Point Text in a PDF Can Siphon Jira Data Out Through Atlassian’s Rovo
View source article
Aioapex
Atlassian's Rovo AI assistant can be hijacked to leak Jira and Confluence data
View source article
Decrypt
Hidden Text in PDFs Is Hijacking This AI Assistant - Decrypt
View source article
The-decoder
Hidden text in a PDF is enough to steal sensitive data through Atlassian's AI agent Rovo
View source article

Featured stories

View more in AI assistants & chatbots

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

OpenAI launches Dots, always-on AI agents that work across 4,000+ apps

Sep 29, 2026 · 14 sources

OpenAI launches Space collaborative workspace and slides feature, competing with Microsoft office suite

Sep 29, 2026 · 13 sources

White House launches America.gov AI chatbot to help navigate government services

Sep 29, 2026 · 7 sources

Story comments

Loading comments…

Topics

AI assistants & chatbotsAI privacy & surveillanceEnterprise AI securityAI securityPrompt injectionData exfiltration

Featured stories

View more in AI assistants & chatbots

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

OpenAI launches Dots, always-on AI agents that work across 4,000+ apps

Sep 29, 2026 · 14 sources

OpenAI launches Space collaborative workspace and slides feature, competing with Microsoft office suite

Sep 29, 2026 · 13 sources

White House launches America.gov AI chatbot to help navigate government services

Sep 29, 2026 · 7 sources