- Sources: primary, discussion
- Summary: PromptArmor demonstrates a chain that starts with a user-uploaded file carrying a hidden injection, which drives Rovo to read tenant Jira and Confluence data and send it to an attacker-controlled destination. The writeup names external Atlassian data, web data and third-party connectors as other possible injection sources. It carries a dated disclosure timeline and states no fix exists 74 days after disclosure. Rovo is a hosted product and the writeup names no affected versions.
- Why it matters: Turning off web search for Rovo does not close this, because the setting removes the search tool and leaves the URL-open tool that performs the exfiltration.
- Follow-up: Track an Atlassian patch or advisory.
send feedback on this story