PromptArmor
aidefend-sf0038
Atlassian Rovo Document Prompt Injection and URL Exfiltration
- Autonomous Agents
- Copilot & SaaS
- RAG & Knowledge Systems
- Data Exfiltration
PromptArmor showed that hidden instructions in an uploaded document could make Rovo search Jira and Confluence, append retrieved data to an attacker-supplied URL, and open that URL through a retrieval capability that remained available when web search was disabled. PromptArmor reported the path unresolved when it published on August 5, 2026.
Mapped threat techniques
AML.T0051.001LLM Prompt Injection: IndirectAML.T0053AI Agent Tool InvocationAML.T0077LLM Data LeakageAML.T0025Exfiltration via Cyber Means