Security firm PromptArmor shows how hidden instructions in a PDF can hijack Atlassian's AI agent Rovo, silently forwarding sensitive data from Jira and Confluence to an external server. The attack needs no user confirmation and leaves no trace.

Atlassian Rovo prompt injection can send Jira and Confluence data to attacker servers. One path is fixed; another remained unresolved on August 5.

The RovoBlast attack method abused a vulnerability in Atlassian’s Rovo AI to steal sensitive Confluence, Jira and SharePoint data.