A Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
At the DEF CON 34 conference, cybersecurity researchers from Varonis Threat Labs revealed a devastating one-click vulnerability in Rovo, an enterprise AI assistant developed by Atlassian. Dubbed “RovoBlast,” this flaw allowed attackers to inject malicious instructions directly into a user’s live AI session with just one carefully crafted link. The implications are alarming: any organization using Rovo may be at risk of having sensitive data exfiltrated.
Atlassian’s Rovo is designed to act as an AI layer across multiple tools and platforms, including Jira, Confluence, Bitbucket, Slack, Microsoft 365, and Google Workspace. This integration enables Rovo to perform complex tasks autonomously, which ultimately led to the discovery of the vulnerability. The exploit leveraged a URL parameter called “rovoChatPrompt,” which allows users to pre-fill content directly into Rovo’s chat window.
The Varonis researchers discovered that they could inject malicious prompts into Rovo using this parameter without needing any special permissions or bypassing security measures. In fact, they found that even if the organization ID part of the URL was left blank, Atlassian would still route the request to the victim’s default organization, providing no warning that their session had been compromised.
The potential for data leakage is vast. When asked what data it could see, Rovo revealed access to a wide range of sensitive information, including Jira tickets, Confluence pages, Bitbucket repositories, and more. The actual data exfiltration came from ResearchAgent, one of Rovo’s built-in tools designed to conduct multi-source web research. Once an attacker’s prompt was seeded through the malicious link, ResearchAgent could pull internal data and push it out to the open web in a single automated chain.
Varonis demonstrated three separate proof-of-concept scenarios, exfiltrating Confluence pages, Jira tickets, and SharePoint content containing personal data. Notably, a single seeded link was enough to trigger the leak; no additional requests or bypass steps were needed. The researchers recommend that organizations limit Rovo’s access to sensitive systems, disconnect unused integrations, and monitor assistant activity logs regularly.
Atlassian has acknowledged the issue and fixed it before the findings were published. While Atlassian is working with customers to implement protective controls on their instances, it’s essential for users to remain vigilant. As AI-powered tools become increasingly ubiquitous in enterprise environments, this vulnerability serves as a stark reminder of the need for robust security measures to prevent similar attacks.
To protect against such vulnerabilities, organizations should prioritize limiting access and monitoring activity logs. It’s also crucial to follow basic security best practices when interacting with AI-powered tools: always verify that any content provided comes from a trusted source, and be cautious of unsolicited links or prompts. By taking these precautions, we can mitigate the risks associated with AI-powered attacks like RovoBlast.
Source: SecurityWeek — 2026-08-08