Attackers can trick Atlassian's Rovo assistant into stealing Jira or Confluence data through hidden instructions. Two security firms found the flaw independently, but only one route is patched so far.
Here's a scenario that should make any Atlassian admin sit up straight: attacker-controlled instructions can trick the company's Rovo assistant into collecting Jira or Confluence data that a signed-in user can access, then quietly ship it off to an external server. That's not a hypothetical concern from a single researcher with a grudge. Two independent security firms uncovered the same behavior through completely different routes. And here's the kicker — only one of those routes is confirmed as patched.
### What's Actually Happening With Rovo
Rovo is Atlassian's AI-powered assistant, designed to help teams search, summarize, and act on information stored across Jira, Confluence, and other connected tools. It's a productivity win when used properly. But like any AI system that reads untrusted content, it opens a new attack surface. The core issue here is prompt injection — a technique where hidden instructions inside documents, files, or web pages get interpreted by the AI as commands from the user.
In this case, an attacker can embed malicious directives into content Rovo processes. When a user asks Rovo to summarize a ticket or scan a Confluence page, the assistant follows the hidden instructions instead. That can mean pulling sensitive project data, customer details, or internal communications — anything the signed-in user has permission to see — and transmitting it to a server the attacker controls.
### Two Firms, Two Paths, One Confirmed Fix
The first firm to flag the issue was PromptArmor, an AI security company that specializes in finding these kinds of weaknesses. They hid the malicious instructions inside an uploaded file that Rovo would read during a normal workflow. Their proof of concept showed the assistant happily collecting data and sending it out, no questions asked.
A second security firm independently discovered the same vulnerability through a different approach. That's often a good sign that a flaw is real and not just a quirk of one testing method. The bad news? While Atlassian has confirmed a fix for one of those exploitation routes, the other remains unconfirmed. That means there's still a window where the attack could work in the wild.
### Why This Matters for Your Team
If your organization relies on Jira or Confluence — and let's face it, most teams do — this isn't just a theoretical worry. Here's what makes it especially dangerous:
- **No malware required.** The attack lives entirely inside content the AI reads. No suspicious executables, no phishing links.
- **It uses legitimate access.** The data exfiltration happens under the signed-in user's permissions, making it harder to detect.
- **It's silent.** The user sees a normal AI response. Nothing looks out of the ordinary.
### What You Can Do Right Now
While we wait for Atlassian to confirm the second patch, there are practical steps to reduce your risk. Start by limiting who can upload files or share external content within your Atlassian environment. Review your Rovo integration settings and consider disabling it for sensitive projects until the fix is verified. Train your team to be cautious about AI summaries of documents from untrusted sources — if it looks odd, double-check the source material.
Also, keep an eye on Atlassian's security advisories. This is the kind of vulnerability that gets patched quickly once confirmed, but the window between discovery and fix is exactly when attackers strike. The good news is that both firms disclosed responsibly, which gives your team time to prepare.
### The Bottom Line
AI assistants are powerful, but they're only as secure as the content they trust. This Atlassian Rovo issue is a stark reminder that convenience and security don't always move at the same pace. Stay updated, stay cautious, and don't assume your data is safe just because the AI says so.