PromptArmor: Atlassian Rovo Zero-Click Exfiltrates Jira and Confluence Data, Still Unpatched 2.5 Months After Disclosure
PromptArmor disclosed publicly on August 5 that Atlassian's Rovo agent can be made to exfiltrate any data reachable through its connectors — Jira and Confluence included — via indirect prompt injection, because Rovo's URL-retrieval tool has no protection against URLs the agent itself generates. The attack defeats organization-level web-search restrictions outright: disabling web search removes the search tool but leaves the tool that opens search results. Timeline: disclosed May 23, acknowledged May 25, follow-ups June 4 and July 29, no further contact, no CVE, and Rovo remains vulnerable — a concrete data point that incumbent AI features are shipping with less security review than the core products they are bolted onto.
↳ Follow the thread