RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data

https://hackernoon.imgix.net/images/InxBRjRIs6M1kdhuWcyNHiiUrxm1-jt83c3x.webp

With access to Jira, Confluence, Microsoft 365, Google Workspace, Slack, and more, RovoBlast shows how a single link turns AI permissions into a low-friction path for data exposure.

Varonis Threat Labs uncovered a vulnerability in Rovo, Atlassian's enterprise AI assistant. Dubbed RovoBlast, a single click on a link triggers the attacker's embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user's session. No jailbreaks, no permission bypass, and no warnings or confirmation.

The same capabilities that make Rovo a powerful tool also make RovoBlast especially dangerous. Rovo operates as an AI layer across the core products in the Atlassian platform, including Jira, Confluence, Bitbucket, as well as other connected SaaS tools like Slack, Microsoft 365, and Google. Atlassian also features autonomous-agent capabilities that can carry out multi-step actions without user involvement.

When AI can search, connect, and act across business systems, the blast radius...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more