Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Atlassian's Rovo AI assistant can be exploited via hidden instructions to steal Jira and Confluence data and send it to attackers; only one of two discovered attack routes has been patched.

Atlassian's Rovo assistant can be tricked into sending Jira and Confluence data to attackers. Two security firms independently discovered this vulnerability via different methods. Only one attack route has been confirmed closed. PromptArmor, an AI security firm, hid malicious instructions in content Rovo reads, such as an uploaded file. This caused Rovo to collect user-accessible data and transmit it to an external server. The second firm's method remains unpatched.