RovoBlast Flaw Lets One Click Force Atlassian AI to Leak Enterprise Data
Brief
A newly disclosed vulnerability in Atlassian’s Rovo enterprise AI assistant could allow attackers to turn a single malicious link into a pathway to exposing sensitive corporate data.
Dubbed RovoBlast by Varonis Threat Labs, the flaw exploited how Rovo Chat handled externally supplied URL parameters. When a logged-in employee clicked a crafted link, attacker-controlled text could be inserted into Rovo’s chat interface as a pre-filled prompt.
That prompt then executed within the victim’s authenticated Rovo session, inheriting their existing access to company resources. The issue was responsibly disclosed to Atlassian and has since been fixed through Bugcrowd’s vulnerability-disclosure process.
Critical RovoBlast Flaw
The attack relied on a “parameter-to-prompt” technique, in which content carried in a URL is treated as trusted AI input.
