RovoBlast: One Click Turns Atlassian's AI Assistant Into a Data Leak
Varonis details RovoBlast, a one-click prompt injection flaw in Atlassian's Rovo AI assistant that can expose sensitive enterprise data.
Varonis Threat Labs disclosed RovoBlast, a vulnerability in Atlassian's Rovo AI assistant that lets a single crafted link inject attacker instructions directly into a user's trusted chat session via the 'rovoChatPrompt' URL parameter. No jailbreak, permission bypass, or confirmation prompt is required—the technique mirrors the Parameter-to-Prompt (P2P) pattern seen earlier in Microsoft Copilot's Reprompt flaw.
Rovo's federated access spans Jira, Confluence, Bitbucket, Slack, Microsoft 365, Google Workspace, relational databases, and over 50 connected platforms. Researchers showed that its ResearchAgent tool—capable of multi-source web research and autonomous multi-step browsing—can chain fetch, transform, and upload actions to exfiltrate internal data to the open web without further user interaction.
Because Rovo cannot be fully uninstalled, organizations can't simply remove the exposed attack surface. The issue was responsibly disclosed to Atlassian, patched, published via Bugcrowd, and presented at DEF CON 34. It underscores how quickly AI assistants with broad access and weak input validation can become high-speed data exfiltration engines.