Atlassian Rovo prompt-injection and link flaw fixed
🛡️ Two security teams found ways to make Atlassian's Rovo assistant exfiltrate data a signed-in user can access. One method used a malicious file with hidden instructions to induce Rovo to gather Jira or Confluence content and send it to an attacker-controlled URL; PromptArmor disclosed this on August 5, 2026 and its remediation status after publication is unconfirmed. The second, dubbed RovoBlast by Varonis, preloads attacker instructions via a rovoChatPrompt URL parameter so a single click from an authenticated user could cause data to be sent out; Atlassian fixed this server-side on July 8, 2026. Both issues rely on data the signed-in user can reach, and administrators can limit exposure by restricting which apps and groups can use Rovo and tightening connector permissions.