🔐
Security 📅 2026-08-09 · 04:34 AM IST ⏱ 3 min read

Atlassian's AI Assistant Found Vulnerable to Data Theft Through Styling Tricks

Researchers discovered attackers can manipulate Rovo to leak confidential Jira and Confluence information from logged-in users.

The Discovery

Security researchers have uncovered a serious vulnerability in Atlassian's Rovo artificial intelligence assistant. The flaw allows bad actors to insert hidden instructions into web pages that trick the AI helper into grabbing sensitive information—like passwords and authentication tokens—directly from users who are logged into their accounts. Two separate security teams discovered the problem through different methods, highlighting how widespread this weakness really is.

Think of it like this: imagine a helpful office assistant who answers questions for you. Now picture someone leaving a note in a corner of the office, written in invisible ink, telling that assistant to secretly copy your passwords and send them elsewhere. That's essentially what's happening here with Rovo.

How The Attack Works

The vulnerability centers on how Rovo processes information from web pages. Attackers can hide malicious commands within the styling and formatting code of websites—the same code that makes pages look pretty. When Rovo reads these pages to help users find information in Jira (project management software) or Confluence (documentation platform), it inadvertently follows these hidden instructions.

Once activated, Rovo can access any data that the logged-in user normally has permission to see. This includes private project details, confidential documents, and critically, authentication tokens—special digital keys that prove who you are online.

What This Means

This is a supply-chain style vulnerability. Even if you personally run a secure operation, attackers don't need to hack you directly. They just need to compromise or inject code into a website that Rovo visits. The damage comes from the trust users place in their tools—Rovo should be helping, not leaking secrets.

Only one of the two identified attack routes has been confirmed as fixed by Atlassian. This means at least one potential entry point remains open.

Why You Should Care

If your organization uses Atlassian products and has enabled Rovo, your team members are potentially at risk. Authentication tokens are particularly dangerous to lose because they're like master keys—someone who steals yours can impersonate you without needing your actual password. They could access projects, modify documents, or exfiltrate data while appearing to be you.

For companies managing sensitive projects, customer information, or proprietary code in Jira and Confluence, this vulnerability could expose everything. The slow patch timeline—with at least one vulnerability still open—adds urgency to this threat.

What You Can Do

Looking Ahead

This discovery reveals how AI assistants introduced into workplace tools create new security surface areas that traditional security approaches might miss. As companies adopt more AI helpers, they'll need to think carefully about what data these systems can access and how attackers might abuse that capability.

Until both vulnerabilities are fully patched and verified, treating Rovo access to sensitive projects as a security risk rather than a convenience feature is the safer choice.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →