Analysis · curated 24 Sep 2026

Two prompt injection paths into Rovo: one fixed (RovoBlast), one open.

Coverage timeline

24 Sep 2026atlassian.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Rovo's connectors reach Jira, Confluence, Bitbucket, Slack, Google Workspace and Microsoft 365, so an unpatched indirect prompt-injection exfiltration channel lets attackers silently siphon data a victim can access without any unusual user action.

Martin Runge's community write-up analyzes two prompt-injection techniques against Atlassian's Rovo AI assistant: RovoBlast (disclosed by Varonis Threat Labs at DEF CON 34), which abused a rovoChatPrompt URL parameter to inject instructions into an authenticated session and was fixed server-side by Atlassian on 8 July 2026; and an indirect prompt-injection method from PromptArmor that hides malicious instructions in content Rovo processes (Jira issues, Confluence, PDFs) and exfiltrates data via Markdown image and URL-retrieval requests. The second path is noted as still open, and disabling org-level web search does not stop it because the URL retrieval tool remains available.