← All stories
● Covered by 3 sources · 3 reportsMedium impact3 negative

Atlassian Rovo AI Vulnerabilities Allowed Data Exfiltration; One Fixed, One Remains

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Atlassian Rovo AI had vulnerabilities allowing data exfiltration.
  • Varonis Threat Labs found 'RovoBlast' via malicious links, now fixed.
  • PromptArmor found indirect prompt injection via uploaded files.
  • PromptArmor's method works even with web search disabled.
  • Atlassian has not confirmed a fix for PromptArmor's reported vulnerability.

Atlassian Rovo AI Vulnerabilities Identified

Atlassian's Rovo AI, an agent operating across products like Jira and Confluence, was found to have vulnerabilities that could lead to data exfiltration. These vulnerabilities allowed attacker-controlled instructions to cause Rovo to collect internal data and send it to external servers.

Two Independent Discovery Routes

Two security firms independently discovered methods for exploiting Rovo. PromptArmor, an AI security firm, identified a method involving indirect prompt injection through uploaded files. Varonis Threat Labs discovered a separate vulnerability, dubbed RovoBlast, which leveraged a malicious link.

RovoBlast Vulnerability and Fix

Varonis Threat Labs' RovoBlast vulnerability allowed a specially crafted link to inject attacker-controlled instructions directly into a user's live AI session. This exploit used the `rovoChatPrompt` URL parameter to preload content into Rovo Chat. Atlassian has confirmed that this specific issue has been fixed.

PromptArmor's Unresolved Findings

PromptArmor's method involved hiding prompt injection instructions within content that Rovo reads, such as an uploaded file. This attack did not require human approval and exploited Rovo's URL retrieval tool, even when web search was disabled. PromptArmor disclosed this to Atlassian on May 23rd, but as of August 5, 2026, Atlassian had not confirmed a fix for this specific vulnerability.

Impact on Atlassian Users

The vulnerabilities could have allowed the exfiltration of sensitive data, such as Jira tickets and Confluence documents, from Atlassian tenants. Rovo functions as an AI layer spanning various Atlassian products and third-party tools, and its autonomous agent features were a factor in the RovoBlast attack.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~11 min · 9 stories · Aug 16

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Varonis Threat Labs discovered a one-click vulnerability, dubbed RovoBlast, in Atlassian’s Rovo AI assistant that allowed attackers to inject instructions via a malicious link, potentially exfiltrating sensitive enterprise data. Atlassian has since fixed the issue, which highlights the risks of AI systems treating external parameters as trusted input.

Atlassian's Rovo AI assistant can be tricked into exfiltrating Jira and Confluence data to external servers through attacker-controlled instructions. Two security firms independently discovered methods for this vulnerability, one of which Atlassian has confirmed as fixed.

Atlassian's Rovo AI agent has vulnerabilities that allow data exfiltration across Atlassian tenants, such as Jira tickets and Confluence documents, through indirect prompt injection. This attack exploits Rovo's URL retrieval tool, even when web search is disabled, and does not require human approval, posing a risk to sensitive data within Atlassian products.