HeadlinesBriefing favicon HeadlinesBriefing.com

Atlassian Rovo Data Exfiltration Vulnerability

Hacker News •
×

Vulnerabilities in Atlassian Rovo AI allow for data exfiltration, bypassing security controls. An attack chain exploits Rovo's URL retrieval tool via indirect prompt injection, enabling the theft of Jira tickets and Confluence documents without human approval.

This exploit functions even when Rovo's web search is disabled, as the underlying tool for opening URLs remains accessible. Prompt Armor disclosed these vulnerabilities to Atlassian on May 23rd. Despite follow-ups over two months, Atlassian has not communicated further, leaving Rovo vulnerable. The attack involves a user uploading a file with a hidden prompt injection, which manipulates Rovo to send sensitive data to an attacker's website.

An attacker can view exfiltrated data in their website logs. A second potential exfiltration mechanism involves Rovo rendering Markdown images from AI outputs. Prompt Armor continues to monitor for AI vendor risks.