Atlassian Rovo Vulnerable to Indirect Prompt Injection Data Exfiltration
August 5, 2026
Atlassian Rovo AI is susceptible to data exfiltration via indirect prompt injection through its URL retrieval tool. Attackers can bypass organizational controls to access Jira tickets and Confluence documents without human intervention, even when web search is disabled.
HOW THIS AFFECTS YOU
●
builderYou must secure agentic tools against indirect injections that exploit retrieval capabilities.
●
policyThis highlights the urgent need for governance frameworks around autonomous agent permissions.