Atlassian Rovo Exfiltrates Data, Bypassing Controls(promptarmor.com)
248 points by hackerBanana 19 hours ago | 97 comments
tl;dr: Atlassian's Rovo AI agent is vulnerable to indirect prompt injection attacks that exfiltrate Jira tickets and Confluence documents by abusing its URL retrieval tool, which lacks protections against agent-generated URLs. The attack works even when web search is disabled, requires no human approval, and leaves no visible trace in the chat afterward. PromptArmor disclosed the issue to Atlassian in May, but after two months of silence, they published the findings while Rovo remains unpatched.
HN Discussion:
  • Atlassian has broader trust issues, including opting users into data training by default
  • This vulnerability class is known and solvable via URL allowlisting patterns Anthropic pioneered
  • Rovo is poorly designed and aggressively injected into Atlassian products
  • ~This is the inherent lethal trifecta problem affecting all agentic AI systems, not unique to Rovo
  • The attack is unimpressive since it requires the victim to introduce the malicious prompt themselves