Atlassian's AI Assistant Rovo Could Be Tricked Into Leaking Jira and Confluence Data
Security researchers have discovered that Atlassian's Rovo AI assistant can be tricked into collecting sensitive data from Jira and Confluence and sending it to an outside server controlled by attackers. Two separate security firms uncovered this issue independently, each using a different method to manipulate the assistant.
One firm, PromptArmor, demonstrated the flaw by hiding malicious instructions inside content that Rovo reads, such as an uploaded file. Because Rovo processes this content as part of its normal operation, it can be manipulated into pulling data the signed-in user has access to and quietly exfiltrating it. This type of attack, known as a prompt injection, exploits the AI's inability to distinguish between legitimate user requests and hidden commands embedded in content.
While Atlassian has reportedly closed one of the two attack routes identified by researchers, the other reportedly remains open, meaning the risk has not been fully eliminated. For businesses using Atlassian's suite of collaboration tools, this highlights a growing concern: AI assistants integrated into everyday business software can become a new pathway for data theft if not properly secured against manipulation.