← Blog · · df00tech

Atlassian Rovo AI Assistant Can Be Manipulated Into Exfiltrating Jira and Confluence Data

security-news technique

Security researchers have reported that Atlassian's Rovo AI assistant can be manipulated via prompt injection into collecting Jira or Confluence data accessible to a signed-in user and sending it to an external, attacker-controlled server.

What Was Reported

According to The Hacker News, two security firms independently discovered this behavior through different attack routes. One firm, PromptArmor, demonstrated the technique by hiding malicious instructions inside content that Rovo reads — reportedly via an uploaded file. Notably, only one of the two discovered routes has been confirmed as closed by Atlassian; the status of the other is not specified in current reporting.

Why It Matters

This is an indirect prompt injection issue: the attacker doesn't need direct access to a victim's account. Instead, they plant instructions in content the AI assistant will ingest (such as an uploaded file), and Rovo — acting with the permissions of the signed-in user — can be induced to gather and exfiltrate data the user is entitled to see. Organizations using Rovo across Jira and Confluence workspaces should treat this as a live concern, particularly given that at least one exploitation path may remain unaddressed as of this reporting.

What Defenders Should Watch For

  • Review what content sources (uploaded files, external links, third-party integrations) are fed into Rovo or similar AI assistants connected to Jira/Confluence.
  • Monitor for anomalous outbound network activity or API calls originating from AI-assistant service accounts/integrations, especially requests to unfamiliar external domains.
  • Audit Rovo's data access scope per user and consider tightening permissions where broad workspace access isn't necessary.
  • Watch for unusual patterns of bulk data retrieval through AI assistant interfaces that don't match typical user query behavior.
  • Track vendor guidance from Atlassian closely, since the confirmed-fixed status applies to only one of the two reported routes.

Developing Story

This is net-new intelligence and details are still emerging, including the full scope of affected configurations and Atlassian's remediation timeline. For the latest information, see the original report at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.