RovoBlast, the One-Click Flaw That Can Make Atlassian’s AI Exfiltrate Data

Varonis Threat Labs has detailed RovoBlast, a critical vulnerability in Atlassian Rovo that allows attackers to inject controlled instructions into a

RovoBlast, the One-Click Flaw That Can Make Atlassian’s AI Exfiltrate Data
AI

Illustrative image generated with AI

A Manipulated Link Controls Rovo’s Prompt

Varonis Threat Labs has detailed RovoBlast, a critical vulnerability in Atlassian Rovo that allows attackers to inject controlled instructions into a victim’s AI session.

The exploit abuses the rovoChatPrompt URL parameter, which pre-populates the chat message. An attacker can therefore craft a link containing a prompt injection. The organization ID is not required: Atlassian still routes the request to the user’s default organization without clearly indicating that the content originated externally.

Known as parameter-to-prompt injection (P2P), the technique requires no jailbreak, permission bypass, or request chains. A single click can be enough.

ResearchAgent’s Role in Data Exfiltration

The attack becomes practical when an authorized user provides Rovo with untrusted content containing malicious instructions. ResearchAgent, a component capable of conducting autonomous web research, may interpret those instructions as part of its assigned task.

In this scenario, the agent can:

  • search connected sources for data;
  • summarize the information it retrieves;
  • access arbitrary websites;
  • publish the results online.

Rovo’s autonomous features can also chain multiple operations without requesting additional user confirmation. The prompt injection therefore abuses the agent’s operational capabilities rather than directly bypassing permissions: Rovo acts with the permissions already available to the account.

Potentially Exposed Data and Integrations

Varonis demonstrated the exfiltration of Confluence pages, Jira tickets, and SharePoint content containing personal data. The potential scope also includes information stored in:

  • Bitbucket and Slack;
  • Microsoft 365 and Google Workspace;
  • relational databases;
  • uploaded files;
  • web pages and archived content.

Atlassian Rovo and its ResearchAgent are affected. The exact impacted versions have not been disclosed.

The impact depends on the enabled integrations, the data accessible to the user, and the active autonomous features. The attacker therefore does not need to already possess the organization’s credentials, but must convince an authorized user to use Rovo with malicious content.

Remediation and Customer Guidance

Varonis reported the vulnerability to Atlassian, which fixed the issue before the findings were published. No version numbers or CVE identifier have been provided; customers should verify the remediation status and applied updates directly in their environments.

Atlassian classifies RovoBlast as part of the broader prompt injection category and compares its operational mechanism to a phishing attack. To reduce the risk, organizations should:

  • restrict the systems and repositories accessible to Rovo;
  • disconnect unused integrations;
  • segregate legal, human resources, and finance environments;
  • disable unnecessary browsing and multi-step automations;
  • regularly review the assistant’s activity logs;
  • use Rovo only with content from trusted sources;
  • train authorized users on prompt injection and phishing techniques.

The combination of manipulated instructions and autonomous browsing makes it especially important to monitor the web destinations contacted by the agent and the data it transfers.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →