Atlassian Rovo Exfiltrates Data, Bypassing Controls

260 points · 110 comments on HN · read original →

Points and comments are a snapshot, not live.

Attackers can exfiltrate Jira and Confluence data via Rovo's URL retrieval tool.

PromptArmor disclosed a vulnerability in Atlassian's Rovo AI that enables data exfiltration via indirect prompt injection. The attack exploits Rovo's insecure URL retrieval tool, which lacks protections against dynamically created URLs, allowing attackers to append sensitive data to URLs. This works even when web search is disabled. PromptArmor reported the issue on May 23, 2026; as of August 5, 2026, Atlassian had not patched it.

A second exfiltration vector exists via insecure markdown image rendering.

What commenters are saying

Commenters expressed strong distrust of Atlassian, with many calling the company's products unusable and its AI features bloated. Specific complaints included Rovo's slowness and inaccurate summaries (e.g., hallucinating acronyms). Some noted alternatives exist (e.g., Linear, Notion, self-hosted MediaWiki). One commenter said Atlassian's stock dropped from $458 (2021) to $112 now.

Several commenters observed that prompt injection vulnerabilities are common across all agentic AI tools, not unique to Rovo.