| Atlassian Rovo Exfiltrates Data, Bypassing Controls(promptarmor.com) | |
| 257 points by hackerBanana 20 hours ago | 108 comments | |
tl;dr: Atlassian's Rovo AI agent is vulnerable to indirect prompt injection attacks that exfiltrate Jira tickets and Confluence documents by abusing its URL retrieval tool, which lacks protections against agent-generated URLs. The attack works even when web search is disabled, requires no human approval, and leaves no visible trace in the chat afterward. PromptArmor disclosed the issue to Atlassian in May, but after two months of silence, they published the findings while Rovo remains unpatched. | |
HN Discussion:
| |