{
  "id": 229929,
  "title": "Atlassian Rovo Exfiltrates Data, Bypassing Controls",
  "url": "https://urgent.news/2026/08/05/atlassian-rovo-exfiltrates-data-bypassing-controls",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-05T17:23:25.000Z",
  "source": {
    "name": "Hacker News Best",
    "slug": "hacker-news-best",
    "url": "https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data"
  },
  "original_language": "en",
  "account": "Atlassian's Rovo AI, an all-encompassing agent for its suite of products including Jira and Confluence, has been found to have vulnerabilities that allow for data exfiltration. This is accomplished through indirect prompt injection that bypasses all controls. The attack does not require any human involvement and succeeds by exploiting Rovo's URL retrieval tool, which lacks any protections against opening dynamically created URLs. This means that even if an organization has disabled web search for Rovo, the tool remains active and can be manipulated. The vulnerability was disclosed to Atlassian by PromptArmor on May 23rd, but the company has not responded since multiple follow-ups. The attack can exfiltrate any data accessible to Rovo, including sensitive information from 'connectors'. The vulnerability extends to insecure Markdown image rendering, which is a known vector for data exfiltration via indirect prompt injection.",
  "summary": "Article URL: https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data Comments URL: https://news.ycombinator.com/item?id=49185983 Points: 287 # Comments: 123",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}