VMTech
Discuss a project

Atlassian Rovo prompt-injection reports expose data exfiltration paths

Atlassian Rovo prompt-injection reports expose data exfiltration paths

Atlassian has fixed RovoBlast, a one-click prompt-injection flaw in Rovo Chat that could have sent Jira, Confluence and connected-app data available to an authenticated user to an attacker-controlled server. Bugcrowd records that Atlassian deployed a server-side fix on July 8, 2026, and that reporter Varonis Threat Labs validated it. The P2 report received a $6,000 bounty.

A separate finding from AI security firm PromptArmor described a content-borne route that it said remained effective when published on August 5. In that demonstration, concealed instructions in an uploaded file caused Rovo to collect data from Jira and Confluence and append it to an attacker URL. The attacker could then retrieve the data from server logs.

Two routes, different remediation status

Varonis called its finding RovoBlast. Its proof of concept used the rovoChatPrompt URL parameter to preload a full prompt into Rovo Chat. One click by a signed-in user could make Rovo act with that user’s privileges, place accessible information in the path of an attacker-controlled image URL and fetch it. Varonis demonstrated exfiltration of a private API key from Confluence and tested the technique against Jira, SharePoint and Outlook connectors.

The Bugcrowd record provides a clear closure status for that link-based route: it is resolved on Atlassian’s side, with no customer patch identified. Neither disclosure had a CVE identifier, and neither appeared in NVD or CISA’s Known Exploited Vulnerabilities catalog as of August 8.

PromptArmor’s report concerns indirect prompt injection rather than a preloaded chat link. A user still has to give Rovo poisoned content and submit an ordinary request, such as asking it to organise Jira tickets. PromptArmor’s narrower claim is that the ensuing exfiltration did not need a separate approval step. It also said disabling Rovo web search did not stop the chain because the outbound retrieval used a separate capability.

Access scope remains the practical control

The findings do not demonstrate a tenant-wide authorization bypass. Rovo follows permissions in Atlassian products and connected third-party applications, so the exposed material is what the signed-in victim can access. That makes account permissions, connector scope and AI feature availability central to the risk assessment. The pattern also fits the concern around trusted assistant instruction abuse risks when a trusted assistant is induced to act on attacker-supplied instructions rather than user intent.

Rovo is enabled by default for apps on Standard, Premium and Enterprise plans, and Atlassian says organisations can block Rovo features for supported apps. Enterprise customers can manage access by app and user group. Atlassian cautions that disabling one Jira-family app does not remove shared Rovo Search, Chat and Create capabilities if another Jira app on the same site remains enabled.

What organisations should do

The confirmed RovoBlast issue requires no local patch because Atlassian fixed it server-side. For the separate content-borne report, whose status after August 5 is not confirmed, organisations can restrict Rovo to necessary apps and groups, tighten underlying permissions and connector reach, and avoid treating the web-search setting alone as a complete security boundary.

#atlassian#rovosecurity#promptinjection#datasecurity
Open analytics
On the site 4 views
min read 4 08.08.2026
Instagram

Atlassian Rovo prompt-injection reports expose data exfiltration paths

Open the post on Instagram ↗