A researcher disclosed in May 2026 that Atlassian's Rovo AI agent can be tricked by a hidden prompt injection into exfiltrating Jira tickets and Confluence documents to an attacker's website, and despite an initial acknowledgment, the flaw is still unpatched as of this week's public disclosure.
Read the full story: Atlassian Rovo AI Still Leaks Jira Data via Prompt Injection →
Transcript
Security researchers just published a working exploit that turns Atlassian's Rovo AI agent into a tool for stealing your own Jira tickets and Confluence docs. Here's how it works. A hidden instruction gets buried inside an uploaded file, invisible to you. You ask Rovo to organize your tickets, and the injection hijacks that request, making Rovo build a URL with your sensitive data appended to it, then call its own tool to open that URL. The attacker doesn't need you to click anything, they just read their own server logs. Turning off web search doesn't stop it either, that setting doesn't remove the vulnerable tool. PromptArmor disclosed this to Atlassian back in May. Two months of silence later, they published it publicly, and as of right now, Rovo is still vulnerable.