Atlassian’s Rovo AI assistant has two separate prompt injection vulnerabilities enabling data exfiltration from Jira and Confluence. PromptArmor disclosed a content-based attack (malicious instructions embedded in uploaded files) on May 23; Atlassian was notified but the flaw remains unpatched as of August 5. Varonis independently discovered a URL parameter injection variant, RovoBlast, which Atlassian patched server-side July 8.
The timing disparity is telling. Two months between disclosure and publication with no patch for the content-based flaw, versus a faster fix for parameter injection, suggests Atlassian is treating these attack classes differently. Whether that reflects different severity assessments or different handling priorities remains unclear. There’s also a false-security trap: organizations that disable Rovo’s web-search setting believe they’ve cut off external URL access. They haven’t. The underlying URL retrieval capability persists, leaving Rovo’s access to 50+ platforms (Jira, Confluence, Slack, Microsoft 365, Google Workspace) as a live exfiltration channel.
Sources: Atlassian Rovo Exfiltrates Data • RovoBlast
Coverage: Atlassian Rovo Can Be Tricked Into Exfiltrating Jira and Confluence Data
Related on this blog: [AUTO] AI-Generated Patches Fail at Scale • [AUTO] Langflow RCE Added to KEV After a Month of Silence • [AUTO] Guardrails Are Usability Theater