The injection manipulates Rovo to submit Jira tickets and Confluence documents to the attacker’s website
Rovo's URL retrieval tool is insecure: there are no protections against opening a URL that has been dynamically created by the agent. Here, Rovo is manipulated to append sensitive data to an attacker's URL. When Rovo calls the insecure tool to open the URL, the attacker's site logs the request, including the appended sensitive data.
Note: This attack succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results.
If the user returns to the chat later, they see the agent's suggested ticket updates, but no evidence of the attack.