Atlassian Rovo Exfiltrates Data, Bypassing Controls

Aug 06, 2026 12:23 AM - 2 hours ago 1

The injection manipulates Rovo to taxable Jira tickets and Confluence documents to the attacker’s website

Rovo's URL retrieval instrumentality is insecure: there are nary protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append delicate information to an attacker's URL. When Rovo calls the insecure instrumentality to unfastened the URL, the attacker's tract logs the request, including the appended delicate data.

Rovo is manipulated by the injection to taxable Jira and Confluence information to the attacker's URL.

Note: This onslaught succeeds moreover if an statement has abnormal web hunt for Rovo. This is because the web hunt mounting fails to region the instrumentality for opening the hunt results.

The organization-wide 'Enable web search' mounting for Rovo is toggled off.

If the personification returns to the chat later, they spot the agent's suggested summons updates, but nary grounds of the attack.

If the personification later reopens the chat, each grounds is gone and output appears normal.
More