अपराध
This Succeeds Even When Web Search Is Disabled Organization-wide, As the Setting Fails to Remove the Tool for Opening Search Results

Security firm PromptArmor disclosed that Atlassian's Rovo AI agent contains vulnerabilities enabling data exfiltration across an Atlassian tenant via indirect prompt injection, without human approval. The attack exploits Rovo's URL retrieval tool, which lacks protections against dynamically created URLs, allowing sensitive data from Jira tickets and Confluence documents to be appended to an attacker's URL and logged on their site. This succeeds even when web search is disabled organization-wide, as the setting fails to remove the tool for opening search results.
PromptArmor reported the issues to Atlassian on May 23rd; Atlassian acknowledged and assigned a case number but has not communicated further after more than two months of follow-ups, leaving Rovo vulnerable. The attack can exfiltrate any data the agent can access, including via connectors, and Rovo also renders Markdown images from AI outputs, another known exfiltration vector.
स्रोत: Hacker News