<Post

Atlassian Rovo Exfiltrates Data, Bypassing Controls

PromptArmor found that an indirect prompt injection can make Atlassian Rovo exfiltrate Jira and Confluence data through an attacker-controlled URL, even with web search disabled. A dynamically generated link is enough; rendered Markdown images provide another possible exfiltration path. The report says Atlassian was notified on May 23 and had not communicated a fix after more than two months.

HN commenters noted that a deterministic allowlist of user-entered or trusted-tool URLs could block this class of attack, while others stressed that leaving a URL-open tool enabled defeats disabling search. The broader lesson is that tool scope, not just prompt filtering, defines an agent’s security boundary.