Atlassian Rovo assistant can be tricked into leaking Jira and Confluence data
Two security firms showed that Atlassian's Rovo AI assistant can be steered by hidden instructions into collecting Jira and Confluence data a signed-in user can access and sending it to an outside server. PromptArmor concealed the instructions in a document Rovo reads, so asking it to organize tickets makes it gather internal data and leak it through a URL request, with no approval step and even with web search disabled. Varonis used a chat URL parameter to preload instructions, so one click ran them with the user's privileges. Atlassian fixed the link-based path server-side, but the content-based path was not confirmed fixed at disclosure.
- Check
- Scope which users, groups, and apps can use Rovo and which data it can reach, and treat documents and pages it processes as capable of carrying hidden instructions.
- Affected
- Organizations using Atlassian Rovo across Jira and Confluence; hidden instructions in content the assistant reads can make it exfiltrate tickets, pages, and connected data under a legitimate user's access.
- Fix
- Limit Rovo's access and the connectors it can reach, restrict who can enable it, monitor for unusual outbound requests from the assistant, and treat all content it ingests as untrusted input.