Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
Critical RovoBlast vulnerability in Atlassian's Rovo AI allowed one-click data exfiltration.
Summary
Varonis researchers discovered a critical one-click vulnerability, dubbed RovoBlast, in Atlassian's Rovo AI assistant. The flaw allowed specially crafted links to inject attacker-controlled instructions into live AI sessions, enabling the exfiltration of sensitive data from Jira, Confluence, and SharePoint without user interaction. Atlassian has since patched the vulnerability.
Full text
DEF CON — Varonis Threat Labs has disclosed a one-click vulnerability in Rovo, Atlassian’s enterprise AI assistant, that let a specially crafted link seed attacker-controlled instructions directly into a user’s live AI session. Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, relying on the fact that the assistant simply treated externally supplied parameters as trusted input. Rovo functions as an AI layer spanning Jira, Confluence, Bitbucket, and third-party tools such as Slack, Microsoft 365, and Google Workspace. It also carries autonomous agent features capable of completing multi-step tasks with no further user involvement, which is what enabled the RovoBlast attack. [ Read: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones ] The exploit leveraged a URL parameter called rovoChatPrompt, which pre-fills content straight into Rovo’s chat window. Varonis researchers describe this attack path as parameter-to-prompt (P2P) injection, which they previously reported in Microsoft Copilot as Reprompt in January. Researchers noticed that the organization ID part of the URL could be left blank and Atlassian would still route the request into the victim’s own default organization, all without any warning or indicator that the session had been seeded by an outside source.Advertisement. Scroll to continue reading. To gauge the potential blast radius, the researchers simply asked Rovo what data it could see. The AI’s answer included Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded files, web pages, and archived content. The actual leakage came from ResearchAgent, one of Rovo’s built-in tools, which can autonomously conduct multi-source web research and navigate across arbitrary sites. Once an attacker’s prompt was seeded through the malicious link, that same capability let Rovo pull internal data and push it out to the open web in a single automated chain. The team demonstrated the technique in three separate proof-of-concept scenarios: exfiltrating Confluence pages, Jira tickets, and SharePoint content containing personal data. Notably, the researchers found that a single seeded link was generally enough to trigger the leak. The attack didn’t require chaining multiple requests or any additional bypass steps to get Rovo to retrieve and summarize sensitive data. Varonis disclosed RovoBlast to Atlassian, which fixed the issue before the findings were published. The researchers recommend that organizations limit which systems Rovo can reach, disconnect unused integrations, wall off sensitive areas such as legal, HR, and finance, disable browsing or multistep automation features that aren’t in active use, and pair this with routine monitoring of assistant activity logs. An Atlassian spokesperson provided the following statement to SecurityWeek: The security of our customers’ data is our highest priority. We are working with customers to implement protective controls on their instances. This is an ongoing and evolving responsibility, and we are actively working on and investing in additional solutions. For the vulnerability to be exploited, a user with access to a customer’s Atlassian instance must provide untrusted content with a prompt injection to Rovo. This is a class of attack that affects AI systems across the industry. Similar to any phishing-type attack, we recommend customers follow security best practices and verify that any content provided to their Atlassian apps comes from a trusted source. Varonis presented the research at DEF CON 34 on Friday. A technical write-up is available on the Varonis blog. Related: Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts Related: Meta AI Hacked External Systems During Cybersecurity Testing Related: Atlassian, Splunk Patch Critical Vulnerabilities Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X PostsMeta AI Hacked External Systems During Cybersecurity TestingHow a $50,000 Exploit Chain Turned Bixby Against Samsung Phones New Attack Methods Enable Malware to Hijack Passkey-Protected AccountsCybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data Water Sector Cyberattacks Reportedly Hit at Least 12 StatesTP-Link Omada ZTP Vulnerabilities Chain Into Full Network TakeoverMicrosoft Bug Bounty Program: $20 Million Paid to 500 Researchers Latest News In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall StreetVishing Extortion Group UNC6671 Rebrands After Making MillionsTruck Brake Controller’s Safety Recall Doubled as Hidden Security FixBlack Hat USA 2026 – Summary of Vendor Announcements (Part 4)Microsoft, Apple Release Fresh Security Updates3.8 Million Impacted by Unlimited Technology Systems Data BreachCritical Vulnerabilities Patched With Chrome 151 UpdateSnowflake Hacker Pleads Guilty in US Court Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email