One-click flaw in Atlassian Rovo AI exposed enterprise data

A one-click vulnerability in Atlassian’s Rovo AI let attackers seed prompts via the rovoChatPrompt URL parameter, enabling the assistant to access and exfiltrate enterprise data.

Varonis Threat Labs disclosed a one-click vulnerability in Atlassian’s Rovo AI that allowed attackers to seed attacker-controlled instructions into a user’s live AI session. The flaw, named RovoBlast by researchers, relied on Rovo treating externally supplied URL parameters as trusted input and required no jailbreak or permission bypass.

Researchers described the technique as parameter-to-prompt (P2P) injection. A specially crafted link pre-filled Rovo’s chat window with attacker-controlled instructions through a rovoChatPrompt URL parameter. Varonis found that leaving the organization ID portion of the URL blank still routed the request into the victim’s default organization without any visible warning that the session had been seeded externally. Varonis presented the findings at DEF CON 34 and published a technical write-up.

Rovo operates across Jira, Confluence and Bitbucket and integrates with third-party services such as Slack, Microsoft 365 and Google Workspace. The assistant includes autonomous agent features, including a ResearchAgent tool that can perform multi-source web research and navigate sites without further user action. Varonis showed that once a malicious prompt was injected via the URL parameter, ResearchAgent could retrieve internal documents and then publish or export their contents in an automated chain.

To assess what Rovo could access, researchers asked the assistant directly. Rovo listed Jira issues, Confluence pages, Bitbucket repositories, Slack messages, files stored in Google Workspace and Microsoft 365, relational databases, uploaded files, web pages and archived content. Varonis produced proof-of-concept attacks that exfiltrated Confluence pages, Jira tickets and SharePoint documents containing personal data. In most cases a single seeded link was sufficient to trigger data retrieval without additional requests or bypass steps.

Varonis disclosed the vulnerability to Atlassian and the company deployed a fix before the research was published. Atlassian provided a statement emphasizing that customer data security is a top priority, that it is working with customers to implement protective controls, and that exploitation requires a user with access to an Atlassian instance to supply untrusted content to Rovo. The company advised customers to follow standard security practices and verify content sources for apps.

Varonis recommended that organizations limit which systems Rovo can reach, disconnect unused integrations, restrict the assistant from sensitive areas such as legal, human resources and finance, disable browsing or multistep automation features that are not needed, and monitor assistant activity logs for unusual behavior. The researchers noted that prompt-injection attacks affect AI assistants that accept external input without validation and advised reviewing integrations and access controls until input validation and safeguards are strengthened.

Articles by this author