Opening SecureFlowAtlassian Rovo Document Prompt Injection and URL Exfiltration
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

PromptArmor aidefend-sf0038

Atlassian Rovo Document Prompt Injection and URL Exfiltration

  • Autonomous Agents
  • Copilot & SaaS
  • RAG & Knowledge Systems
  • Data Exfiltration

PromptArmor showed that hidden instructions in an uploaded document could make Rovo search Jira and Confluence, append retrieved data to an attacker-supplied URL, and open that URL through a retrieval capability that remained available when web search was disabled. PromptArmor reported the path unresolved when it published on August 5, 2026.

Mapped threat techniques

  • AML.T0051.001 LLM Prompt Injection: Indirect
  • AML.T0053 AI Agent Tool Invocation
  • AML.T0077 LLM Data Leakage
  • AML.T0025 Exfiltration via Cyber Means

Source