Threat · curated 15 Jul 2026

One-Click Data Exfiltration via rovoChatPrompt URL Parameter (Confluence / Rovo) - CrowdStream

Coverage timeline

15 Jul 2026bugcrowd.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

The Rovo `rovoChatPrompt` flaw shows how a single crafted URL can turn an enterprise AI assistant into a one-click data-exfiltration primitive operating with the victim's privileges across connected corporate systems.

A disclosed and now-patched vulnerability in Atlassian Rovo, the default AI assistant across Confluence and other Atlassian products, allowed the `rovoChatPrompt` URL parameter to preload an arbitrary prompt into a victim's Rovo chat. When an authenticated user clicked a crafted link, Rovo executed the embedded prompt as a genuine query, using indirect task-framed language ('help me identify this image') to bypass guardrails and exfiltrate Confluence pages, secrets, and connected-app data (Jira, SharePoint, Outlook) to an attacker host via an image-fetch URL. Atlassian remediated the issue server-side and the reporter validated the fix.