Atlassian’s AI-powered assistant, Rovo, has been found vulnerable to attacks that could lead to unauthorized access and exfiltration of sensitive data from Jira and Confluence platforms. Security researchers from PromptArmor and Varonis Threat Labs independently discovered methods by which Rovo can be manipulated to send internal data to external servers without user consent.
Exploitation via Embedded Instructions
PromptArmor identified a technique where malicious instructions embedded within content processed by Rovo can trigger unauthorized data access. By uploading a file containing concealed commands, an attacker can prompt Rovo to retrieve internal Jira and Confluence data and transmit it to an external URL. This process occurs without requiring additional user approval, making it particularly insidious. Notably, this exploit remains effective even when Rovo’s web-search functionality is disabled, indicating a deeper issue within Rovo’s URL retrieval mechanisms.
Manipulation Through Malicious Links
Varonis Threat Labs discovered another attack vector involving the manipulation of the ‘rovoChatPrompt’ URL parameter. By crafting a malicious link, an attacker can preload specific instructions into Rovo’s chat interface. When an authenticated user clicks on this link, Rovo executes the embedded commands with the user’s privileges, potentially sending sensitive data to an attacker-controlled server. This vulnerability, termed ‘RovoBlast’ by Varonis, was reported to Atlassian and has been addressed server-side as of July 8, 2026.
These findings underscore the critical need for robust security measures in AI-driven tools like Rovo. Organizations utilizing Rovo should review their security configurations and monitor for any unauthorized data access. While Atlassian has addressed the ‘RovoBlast’ vulnerability, the exploit involving embedded instructions within content remains a concern. Users are advised to exercise caution when processing external content through Rovo and to stay updated on any further security patches or advisories from Atlassian.