A security firm says Atlassian AI assistant will quietly ship your Jira tickets and Confluence docs to an attacker using hidden text in PDFs.

Atlassian Rovo prompt injection can send Jira and Confluence data to attacker servers. One path is fixed; another remained unresolved on August 5.

The RovoBlast attack method abused a vulnerability in Atlassian’s Rovo AI to steal sensitive Confluence, Jira and SharePoint data.