Atlassian Rovo Prompt Injection Flaws: One-Click Data Exfiltration Paths Detailed
TechNadu · x · 2026-08-08
Security firms Varonis and PromptArmor independently uncovered indirect prompt-injection vulnerabilities in Atlassian's Rovo assistant.
- Varonis (RovoBlast): Attackers preloaded malicious instructions into a URL parameter. A single click by an authenticated user triggered Rovo to collect and send accessible data to an attacker-controlled server. Atlassian fixed this server-side on July 8.
- PromptArmor: By uploading a file with hidden instructions, Rovo could be tricked into exfiltrating internal data via a URL request. As of Aug 5, this chain still worked even with web search disabled, and its remediation status remains unconfirmed.
No patches are required for customers; mitigation relies on scoping which apps and groups can access Rovo.
Related event: Atlassian Rovo AI Assistant Vulnerable to Prompt Injection(2 posts)→
More from Safety
- Claude's invisible watermarks cracked within hours; override code gets 20k bookmarks — deliprao · 2026-08-24
- Unprompted 2026 AI security conference in Sydney announces first speakers — dyn___ · 2026-08-24
- Debate erupts over lethal military robots vs. failing civilian units — teortaxesTex · 2026-08-24
- Only 1 of 20 Potential Presidential Candidates Answered AI Pause Query — DavidSKrueger · 2026-08-24
- Chinese Transforming Robot Dog Sparks US Trade Policy Criticism — TinfoilTricorn · 2026-08-24
- Turkey blocks at least 12 Grok posts on national security grounds — Unusual_Variation293 · 2026-08-24