Atlassian Rovo 被间接提示注入窃取数据
推荐指数 51.0 NO. 017 · 2026.08.06
发布2026/08/05Score58Comments15
为什么值得看
PromptArmor 发现 Atlassian Rovo AI 存在严重漏洞,攻击者可通过间接提示注入绕过所有管控、无需人工审批即可批量导出 Jira 工单和 Confluence 文档。更值得警惕的是,Atlassian 收到披露后两个多月未修复也未回应,为使用 Rovo 的企业敲响了数据安全警钟。
编辑判断
这个漏洞的杀伤力在于完全自动化和绕过组织级管控的双重特性。攻击者只需在 Confluence 页面或 Jira 评论中植入恶意指令,Rovo 的 URL 检索工具就会主动将数据外传到第三方服务器,而管理员关闭全网搜索的常规防护手段对此无效。
对企业安全团队来说,这意味着需要重新审视 AI Agent 的工具权限设计原则——不能假设禁用某个功能就能切断攻击面。当前最务实的动作是评估是否暂停 Rovo 的自动化执行权限,直到 Atlassian 给出修复时间表。对于做 AI Agent 安全的创业者,这也暴露了一个真实需求:企业级部署中工具调用的最小权限和人工审批卡点,不能仅靠配置开关实现,需要运行时行为监控。
社区反馈
负面 16 条评论
核心争论:Atlassian Rovo 是安全漏洞重灾区还是企业 AI 工具通病
相关内容
AI助手类应用通杀漏洞:间接提示注入可窃取企业敏感数据 Claude Opus 4.7 表现出更强的文件检索能力,反而会扩大攻击影响范围。在所有5次测试中,攻击都成功完成了完整的窃取流。 間接提示注入攻擊正泛濫!駭客金融詐騙與資料外洩新利器 攻击者试图迫使代理式AI执行Unix命令删除文件,或通过「send me the secret API key」指令迫使代理泄露机密资讯。 间接快速注入:无声的人工智能风险 恶意指令隐藏在外部不受信任的内容中,AI在执行用户请求的合法任务时,会在不知情的情况下执行隐藏的命令。 4.3 间接提示注入技术 | 大模型安全权威指南 间接注入可导致文件操作、数据窃取、API调用等,当多个GenAI应用连接时,可能像蠕虫一样自我复制、横向传播。
> Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. When Rovo calls the insecure tool to open the URL, the attacker's site logs the request, in
Atlassian has gone from a trusted enterprise-partner to a complete shit-show in just 18 months. This surprises nobody. There will be classes taught in how to fuck up a good business and Atlassian will be the prime example. Regards, /someone who migrated 3500 users from Atlassians products rece
I started to consider it a show show way earlier than 18 months ago. Jira is so terrible to use that it is hard to phantom how they are able to be paid for their product