Atlassian Rovo Exfiltrates Data, Bypassing Controls

promptarmor.com

76 points by hackerBanana 3 hours ago


htrp - an hour ago

I feel like prompt armor writes the exact same blog post for every agentic tool because they all suffer from the ignore previous instructions prompt injections.

https://www.promptarmor.com/resources/claude-cowork-exfiltra...

https://www.promptarmor.com/resources/google-antigravity-exf...

https://promptarmor.substack.com/p/data-exfiltration-from-sl...

https://www.promptarmor.com/resources/gpt-for-google-sheets-...

https://www.promptarmor.com/resources/notion-ai-unpatched-da...

https://www.promptarmor.com/resources/ramps-sheets-ai-exfilt...

https://www.promptarmor.com/resources/superhuman-ai-exfiltra...

hahahaa - 26 minutes ago

> The victim uploads a file to Rovo that contains a hidden prompt injection

Yeah this attack is possible on all modern agentic systems.

* Access to your private data

* Exposure to untrusted content

* The ability to externally communicate in a way that could be used to steal your data

(https://simonw.substack.com/p/the-lethal-trifecta-for-ai-age...)

And blocking it wholesale reduces usefulness of the agent so it is a tradeoff.

pram - 2 hours ago

I can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere.

It’s objectively worse than using something like Cowork + MCP, AND they injected it into every single page on JIRA and Confluent which has made web browsing way slower while all the junk is loading.

john_strinlai - 2 hours ago

~every ai vulnerability write up boils down to "just ask it do to the thing", but with fancier terms like "indirect prompt injection".

ExoticPearTree - 26 minutes ago

Rovo is funny. It downloads everything it can do Atlassian servers for "analysis". And you're pretty much screwed if you link it to Google Docs or Sharepoint. How do I know this? "Why is an AWS IP downloading all our docs?" question I got about a month ago.

alexaholic - 10 minutes ago

Fwiw Rovo is built on top of Claude

consp - 2 hours ago

It's nice they force rovo now for document/version diff's. Because you need to burn down the rainforest for those. (sarcasm ... for obvious reasons)

- 2 hours ago
[deleted]
automatic6131 - 7 minutes ago

Ahh yes: "when you Rovo, you oh-no my data"

mvdtnz - 17 minutes ago

> Note: This attack succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results.

Wow, great work Atlassian. The web search setting does not disable web search.

formerly_proven - 2 hours ago

> Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. When Rovo calls the insecure tool to open the URL, the attacker's site logs the request, including the appended sensitive data.

khanan - 2 hours ago

Atlassian has gone from a trusted enterprise-partner to a complete shit-show in just 18 months. This surprises nobody. There will be classes taught in how to fuck up a good business and Atlassian will be the prime example.

Regards, /someone who migrated 3500 users from Atlassians products recently due to their "cloud only"-bullshit.

throwaway613746 - 33 minutes ago

[dead]