logoalt Hacker News

Atlassian Rovo Exfiltrates Data, Bypassing Controls

81 pointsby hackerBananatoday at 5:23 PM28 commentsview on HN

Comments

hahahaatoday at 7:54 PM

> The victim uploads a file to Rovo that contains a hidden prompt injection

Yeah this attack is possible on all modern agentic systems.

* Access to your private data

* Exposure to untrusted content

* The ability to externally communicate in a way that could be used to steal your data

(https://simonw.substack.com/p/the-lethal-trifecta-for-ai-age...)

And blocking it wholesale reduces usefulness of the agent so it is a tradeoff.

pramtoday at 6:35 PM

I can’t get over how bad “Rovo” is. Somehow more aggressive and useless than Microsoft putting “Copilot” everywhere.

It’s objectively worse than using something like Cowork + MCP, AND they injected it into every single page on JIRA and Confluent which has made web browsing way slower while all the junk is loading.

show 2 replies
john_strinlaitoday at 6:35 PM

~every ai vulnerability write up boils down to "just ask it do to the thing", but with fancier terms like "indirect prompt injection".

ExoticPearTreetoday at 7:54 PM

Rovo is funny. It downloads everything it can do Atlassian servers for "analysis". And you're pretty much screwed if you link it to Google Docs or Sharepoint. How do I know this? "Why is an AWS IP downloading all our docs?" question I got about a month ago.

alexaholictoday at 8:10 PM

Fwiw Rovo is built on top of Claude

consptoday at 6:46 PM

It's nice they force rovo now for document/version diff's. Because you need to burn down the rainforest for those. (sarcasm ... for obvious reasons)

mvdtnztoday at 8:02 PM

> Note: This attack succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results.

Wow, great work Atlassian. The web search setting does not disable web search.

formerly_proventoday at 6:23 PM

> Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. When Rovo calls the insecure tool to open the URL, the attacker's site logs the request, including the appended sensitive data.

automatic6131today at 8:13 PM

Ahh yes: "when you Rovo, you oh-no my data"

khanantoday at 6:27 PM

Atlassian has gone from a trusted enterprise-partner to a complete shit-show in just 18 months. This surprises nobody. There will be classes taught in how to fuck up a good business and Atlassian will be the prime example.

Regards, /someone who migrated 3500 users from Atlassians products recently due to their "cloud only"-bullshit.

show 4 replies
mhrsntrktoday at 8:29 PM

[dead]

throwaway613746today at 7:47 PM

[dead]