Security researchers have exposed critical prompt injection vulnerabilities in Atlassian's Rovo AI assistant that allow silent data exfiltration from Jira and Confluence. PromptArmor revealed that attackers can hide invisible commands in uploaded PDFs to force Rovo to transmit sensitive data to external servers. Although Atlassian patched a separate vulnerability reported by Varonis on July 8, 2026, the firm has not patched PromptArmor's May 23 disclosure, leaving Rovo actively vulnerable.
Rovo prompt injection vulnerabilities
- ▪Security firm PromptArmor discovered a zero-click indirect prompt injection vulnerability in Atlassian's Rovo AI assistant that allows data exfiltration without human approval.
- ▪Varonis Threat Labs identified a separate prompt injection vulnerability in Atlassian's Rovo AI assistant, dubbed RovoBlast, which exploits a URL parameter named rovoChatPrompt.
Hidden text attack vectors
- ▪PromptArmor reported that support tickets, web content, or data pulled through third-party connectors can also serve as injection sources to hijack Atlassian's Rovo AI assistant.
- ▪Attackers can hijack Atlassian's Rovo AI assistant by embedding invisible commands, such as white-on-white text in a one-point font, inside uploaded files like PDFs.
URL-based data exfiltration
- ▪Atlassian's Rovo AI assistant renders Markdown images from AI outputs, which PromptArmor identified as a second exfiltration path for data theft.
- ▪The prompt injection vulnerability in Atlassian's Rovo AI assistant exploits its built-in URL retrieval tool, or UrlReadTool, to transmit gathered data to an attacker-controlled server.
- ▪Disabling the web search feature for Atlassian's Rovo AI assistant fails to block data exfiltration because the underlying UrlReadTool remains active.
Jira Confluence data exposure
- ▪The Varonis-discovered RovoBlast vulnerability allows Atlassian's Rovo ResearchAgent tool to autonomously pull data from integrated services including SharePoint, Slack, Google Workspace, and Microsoft 365.
- ▪The prompt injection vulnerabilities in Atlassian's Rovo AI assistant can expose sensitive corporate data, including Jira ticket contents, Confluence page text, private API keys, and workspace member lists.
Atlassian disclosure response timeline
- ▪Atlassian assigned a case number and thanked PromptArmor on May 25, 2026, but failed to communicate further despite follow-ups on June 4, 2026, and July 29, 2026.
- ▪Atlassian shipped a server-side fix for the Varonis-reported RovoBlast vulnerability on July 8, 2026, through its Bugcrowd bug bounty program.
- ▪PromptArmor privately disclosed its discovered vulnerability to Atlassian on May 23, 2026, and published details publicly on August 5, 2026, after Atlassian went silent and left the flaw unpatched.
AI agent security weaknesses
- ▪Security researchers have identified similar indirect prompt injection vulnerabilities in other enterprise AI tools, including a recent flaw affecting Word documents in Microsoft Copilot.
- ▪Indirect prompt injection is a structural weakness affecting AI assistants that process untrusted external content while holding privileged access to internal systems.
Story comments
Loading comments…