Atlassian Rovo leaks Jira and Confluence data, still unpatched

A poisoned file turns the AI agent into an exfil channel — and disabling web search doesn't close the hole. Disclosed in May, still open. What to do now.

Nowline AUG 6 12:00 PM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • A poisoned file, and it mails your tickets out

    A hidden instruction in an uploaded file or a Confluence page hijacks Rovo mid-task: it appends your Jira tickets and Confluence docs to an attacker's URL, then Rovo's own URL-fetch tool opens that link and the attacker's server logs the data. Zero clicks from you beyond the normal request.

  • Turning off web search doesn't save you

    Teams that disabled Rovo's web search assumed they'd cut the leak path. They didn't — the toggle drops search but leaves the URL-opening tool live, so dynamically built links still fire. The one control you'd reach for is the one that doesn't help.

  • Reported in May, still open in August

    PromptArmor disclosed on May 23, Atlassian acknowledged on May 25, then went dark through two follow-ups; the bug was still live when the writeup dropped Aug 5. Separate researchers — a Bugcrowd one-click rovoChatPrompt report and redtrib3 — hit the same class of hole.

  • If your team runs Rovo, do this today

    Assume Rovo is exploitable across Jira and Confluence right now: restrict file uploads into it, watch agent tool calls for outbound URLs you don't recognize, and treat any Rovo answer that touched untrusted content as untrusted itself.

  • It's the lethal trifecta, not one bad product

    Any agent with your private data, exposure to untrusted text, and a way to phone out can be turned into a leak — Simon Willison's "lethal trifecta." Rovo is this week's example; if you're wiring tools into your own agent, keeping those three ingredients apart is the whole game.