A Critical Vulnerability in Atlassian’s Rovo AI Assistant Exposes Enterprise Data to Attackers
A team of researchers at Varonis Threat Labs has uncovered a severe vulnerability in Rovo, the enterprise AI assistant developed by Atlassian. The flaw, dubbed RovoBlast, allows attackers to inject malicious instructions into a user’s live AI session with just one click on a specially crafted link. This exploit has significant implications for organizations that rely on Rovo to integrate their various tools and systems.
Rovo is designed to act as an AI layer across multiple platforms, including Jira, Confluence, Bitbucket, Slack, Microsoft 365, and Google Workspace. One of its key features is the ability to autonomously complete multi-step tasks without further user involvement. Unfortunately, this feature also makes it vulnerable to attacks like RovoBlast.
The researchers discovered that by exploiting a URL parameter called rovoChatPrompt, an attacker could pre-fill content directly into Rovo’s chat window. This “parameter-to-prompt” (P2P) injection attack is similar to one previously reported in Microsoft Copilot as Reprompt. What makes RovoBlast particularly concerning is that it doesn’t require any special permissions or bypass steps; a single seeded link can trigger the leak.
To gauge the potential damage, the researchers asked Rovo what data it could access. The AI’s response was unsettling: Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded files, web pages, and archived content – all within a single automated chain. This means that an attacker could potentially exfiltrate sensitive information from various systems with just one click.
The researchers demonstrated the technique in three separate proof-of-concept scenarios: extracting Confluence pages, Jira tickets, and SharePoint content containing personal data. Crucially, these attacks did not require chaining multiple requests or any additional bypass steps to get Rovo to retrieve and summarize sensitive data.
Fortunately, Atlassian was notified of the vulnerability by Varonis, and they promptly fixed the issue before the findings were published. However, this incident highlights the need for organizations to take proactive measures to secure their AI-powered tools. The researchers recommend limiting Rovo’s access to sensitive systems, disconnecting unused integrations, walling off sensitive areas, disabling browsing or multistep automation features that aren’t in active use, and regularly monitoring assistant activity logs.
As AI technology becomes increasingly pervasive, it’s essential for organizations to understand the security implications of these solutions. While Atlassian has taken steps to address this vulnerability, it’s a sobering reminder that even the most advanced tools can have critical flaws if not properly secured. By following best practices and verifying the trustworthiness of content provided to their AI apps, customers can minimize their exposure to such attacks.
Source: SecurityWeek — 2026-08-08