Attackers can trick Atlassian's Rovo AI into sending Jira and Confluence data to outside servers. Two security firms found the flaw, but only one route is fixed. Learn how to protect your team.
There's a new wrinkle in the world of workplace AI, and it's one that should make any team using Atlassian's Rovo assistant sit up and take notice. Security researchers have found a way to trick this popular AI tool into quietly collecting sensitive information from Jira and Confluence—data that a signed-in user can already access—and then shipping it off to an attacker's server. It's the kind of scenario that sounds like a spy movie, but it's very real, and it's happening right now.
Two separate security firms stumbled upon this behavior independently, using different approaches. That's a big deal because it means this isn't some obscure, one-off quirk. It's a systemic issue that could affect countless organizations relying on Atlassian's suite of productivity tools. The scary part? Only one of those attack routes has been officially confirmed as closed. The other is still a potential open door.
### How the Attack Actually Works
Here's the breakdown in plain English. Rovo is Atlassian's AI-powered assistant, designed to help you find information, summarize documents, and answer questions based on your company's internal data. It's a huge time-saver, but it also creates a new attack surface. The researchers at PromptArmor, an AI security firm, figured out how to hide malicious instructions inside content that Rovo routinely reads—like an uploaded file or a shared document.
When a user asks Rovo a question, the AI doesn't just pull the answer from thin air. It reads through relevant files and pages to piece together a response. If one of those files contains hidden commands, Rovo can be manipulated into following them. In this case, the instructions told Rovo to gather specific pieces of data the user has access to and then send that data to an external server controlled by the attacker. No malware, no phishing email, just a cleverly crafted document.
### Why This Matters for Your Team
Think about what lives in your Jira and Confluence instances. Project plans, customer details, internal roadmaps, employee information, financial forecasts—the list goes on. An attacker who can pull this data doesn't need to break into your network; they just need to get a malicious file in front of Rovo. This is a classic example of a prompt injection attack, where the AI is tricked into doing something it wasn't designed to do.
- **Data exfiltration**: Sensitive info silently leaves your organization.
- **Trust erosion**: Your team loses confidence in the AI tools they rely on daily.
- **Compliance risks**: If you handle regulated data, this could be a nightmare.
### What You Can Do Right Now
Atlassian has reportedly closed one of the identified attack routes, which is good news, but it's not a reason to relax. The second route remains unconfirmed, and new attack vectors are discovered all the time. Here's a practical checklist to harden your defenses:
1. **Audit your uploaded files**: Be cautious about what gets shared in your Atlassian ecosystem, especially from external sources.
2. **Monitor outbound traffic**: Keep an eye on unusual network activity that could indicate data being sent to unknown servers.
3. **Limit user permissions**: The less data a single user can access, the less an attacker can steal through a compromised account.
4. **Stay updated**: Follow Atlassian's security advisories closely and apply patches as soon as they're available.
### The Bottom Line
AI tools like Rovo are incredibly powerful, but they also introduce new risks that traditional security measures don't always catch. This isn't about abandoning these tools—it's about using them with your eyes wide open. The fact that two independent firms found the same vulnerability through different routes tells us this is a pattern, not a fluke. Until the second attack vector is officially closed, treat your AI assistant as a potential weak link and take the necessary precautions. Your data is too valuable to leave that door open. Stay safe out there.