Security researchers found that Atlassian’s Rovo AI assistant could be manipulated through indirect prompt injection, hidden instructions embedded in an uploaded document, into collecting Jira tickets, Confluence pages, and connected third-party data and sending it to an attacker-controlled server without requiring any human approval. Atlassian fixed one variant of the flaw on its servers, but a second, document-based injection path remained unresolved at the time of disclosure. No confirmed real-world exploitation of customer data was reported; the findings were demonstrated as proof-of-concept research.