Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

https://www.securityweek.com/wp-content/uploads/2026/08/Atlassian-Rovo.webp

DEF CON — Varonis Threat Labs has disclosed a one-click vulnerability in Rovo, Atlassian’s enterprise AI assistant, that let a specially crafted link seed attacker-controlled instructions directly into a user’s live AI session.

Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, relying on the fact that the assistant simply treated externally supplied parameters as trusted input.

Rovo functions as an AI layer spanning Jira, Confluence, Bitbucket, and third-party tools such as Slack, Microsoft 365, and Google Workspace. It also carries autonomous agent features capable of completing multi-step tasks with no further user involvement, which is what enabled the RovoBlast attack.

[ Read:How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones]

The exploit leveraged a URL parameter called rovoChatPrompt, which pre-fills content straight into Rovo’s chat window. Varonis researchers describe this attack path as parameter-to-prompt (P2P) injection, which they previously reported in Microsoft...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE