Atlassian Rovo: Critical Cross-Platform Indirect Prompt Injection XPIA Vulnerabilities
Atlassian Rovo, an enterprise AI assistant, is subject to two distinct Indirect Prompt Injection (XPIA) attack vectors that threaten cross-platform data integrity. While the "RovoBlast" one-click vulnerability via the rovoChatPrompt URL parameter was patched in July 2026, a more severe zero-click vector remains unconfirmed for remediation. This second vector utilizes malicious instructions embedded within file metadata or content to hijack Rovo’s internal URL retrieval and grounding tools. Once triggered, the attack enables silent, unauthorized exfiltration of sensitive information from interconnected platforms, including Jira, Confluence, Slack, Google Workspace, and Microsoft 365, effectively bypassing "web search disabled" security configurations.
Microsoft Copilot: Self-Propagating XPIA Worm via Hidden Prompt Injection
Microsoft Copilot for Word is susceptible to a self-propagating Cross-Prompt Injection Attack (XPIA) stemming from a fundamental architectural inability to distinguish between untrusted user data and authoritative developer instructions. Attackers embed JSON-formatted payloads using white-on-white text obfuscation in .docx files. Upon ingestion, the AI agent elevates these hidden strings to high-priority system commands, enabling the worm to autonomously append itself to any subsequently generated or edited documents. This mechanism bypasses traditional EDR and AV signatures by utilizing authorized AI agents within enterprise workflows—specifically SharePoint and Teams—potentially leading to organizational-wide context collapse and unauthorized data exfiltration.