Atlassian Rovo leaks Jira and Confluence data, still unpatched
A poisoned file turns the AI agent into an exfil channel — and disabling web search doesn't close the hole. Disclosed in May, still open. What to do now.

Copy markdown
A poisoned file, and it mails your tickets out
A hidden instruction in an uploaded file or a Confluence page hijacks Rovo mid-task: it appends your Jira tickets and Confluence docs to an attacker's URL, then Rovo's own URL-fetch tool opens that link and the attacker's server logs the data. Zero clicks from you beyond the normal request.
Turning off web search doesn't save you
Teams that disabled Rovo's web search assumed they'd cut the leak path. They didn't — the toggle drops search but leaves the URL-opening tool live, so dynamically built links still fire. The one control you'd reach for is the one that doesn't help.
Reported in May, still open in August
PromptArmor disclosed on May 23, Atlassian acknowledged on May 25, then went dark through two follow-ups; the bug was still live when the writeup dropped Aug 5. Separate researchers — a Bugcrowd one-click rovoChatPrompt report and redtrib3 — hit the same class of hole.
If your team runs Rovo, do this today
Assume Rovo is exploitable across Jira and Confluence right now: restrict file uploads into it, watch agent tool calls for outbound URLs you don't recognize, and treat any Rovo answer that touched untrusted content as untrusted itself.
It's the lethal trifecta, not one bad product
Any agent with your private data, exposure to untrusted text, and a way to phone out can be turned into a leak — Simon Willison's "lethal trifecta." Rovo is this week's example; if you're wiring tools into your own agent, keeping those three ingredients apart is the whole game.