{"data":{"id":"57d713c8-84b8-47cc-a2da-ca21010f376b","title":"Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers","summary":"Atlassian's Rovo assistant can be tricked into sending sensitive data from Jira and Confluence to attackers through two different methods: hiding malicious instructions in documents or URLs. One method (the URL-based attack called RovoBlast) was confirmed fixed by Atlassian on July 8, 2026, but the other method (hiding instructions in uploaded files) remains unconfirmed as patched, with Atlassian's response unclear after the initial disclosure.","solution":"For the URL-based RovoBlast flaw: \"Atlassian fixed it server-side on July 8, 2026, and the reporter validated the fix.\" For the file-based prompt injection attack: The source states that \"the lever for the content-borne path is scoping which apps and groups can use Rovo at all,\" meaning organizations can restrict which applications and user groups have access to Rovo, but no specific patch or version update is confirmed for this vulnerability.","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html","publishedAt":"2026-08-08T08:54:50.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection","data_extraction"],"issueType":"news","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Atlassian Rovo"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-08T08:54:50.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}