Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

Atlassian Rovo AI assistant hit by prompt-injection flaws that leak Jira data

Security researchers disclosed two prompt-injection flaws in Atlassian's Rovo AI assistant that can exfiltrate Jira and Confluence data, one still unresolved as of August 5.

D
Aug 8, 2026 · 1 min read

Two separately disclosed prompt-injection flaws in Atlassian’s Rovo AI assistant can trick the tool into exfiltrating Jira and Confluence data to attacker-controlled servers, with one bug still unresolved months after it was reported.

Rovo is an AI assistant embedded across Atlassian’s Jira and Confluence products. Both flaws share the weakness that has dogged enterprise AI copilots: the assistant treats untrusted content it reads as if it were trusted instructions. Neither attack required a jailbreak or a permission bypass.

Security firm PromptArmor disclosed a content-borne injection chain to Atlassian on May 23 and published its findings on August 5, saying the flaw remained unresolved after follow-ups on June 4 and July 29. The exploit persists even when an administrator disables Rovo’s web-search tool, PromptArmor said.

The other flaw, a one-click bug that Varonis Threat Labs dubbed “RovoBlast,” abused Rovo’s rovoChatPrompt URL parameter to plant attacker-controlled instructions. Atlassian patched it server-side by July 8, and the research was presented at the DEF CON 34 security conference in early August.

Atlassian said “the security of our customers’ data is our highest priority” and that it is working with customers to implement protective controls. The company compared exploitation to phishing, since it requires a user to feed Rovo untrusted content in the first place.

That framing sidesteps the harder question of whether an AI assistant should ever act on instructions hidden in the documents it reads. Both firms demonstrated data exfiltration in controlled research settings rather than in observed attacks, and PromptArmor’s account of the unresolved flaw has not been independently verified. Atlassian has not publicly detailed a fix timeline for it.

The disclosures land as companies wire assistants like Rovo into their most sensitive systems of record, where a single poisoned page could turn a helper into a leak.

More news