RovoBlast: One-Click Flaw in Atlassian Rovo AI Leaked Enterprise Data
Security researchers at Varonis Threat Labs have disclosed a critical one-click vulnerability in Atlassian's Rovo AI assistant that allowed attackers to seed malicious prompts directly into a victim's live AI session through a specially crafted URL. Dubbed RovoBlast and presented at DEF CON, the flaw required no jailbreak or permission bypass, exploiting the fact that Rovo treated externally supplied URL parameters as trusted input. The vulnerability was classified as a parameter-to-prompt (P2P) injection, a technique Varonis previously reported in Microsoft Copilot as "Reprompt" in January 2025.
The exploit leveraged a URL parameter called rovoChatPrompt, which pre-fills content directly into Rovo's chat window. Researchers discovered that the organization ID portion of the URL could be left blank, yet Atlassian would still route the request into the victim's default organization without any warning that the session had been seeded by an external source. The actual data leakage stemmed from ResearchAgent, one of Rovo's built-in autonomous tools capable of conducting multi-source web research across connected platforms including Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded files, and archived content. Once an attacker's prompt was injected, the same agent capability let Rovo pull internal data and push it to the open web in a single automated chain.
The Varonis team demonstrated the attack in three proof-of-concept scenarios: exfiltrating Confluence pages, Jira tickets, and SharePoint content containing personal data. A single seeded link was generally sufficient to trigger the leak, with no need to chain multiple requests or perform additional bypass steps to get Rovo to retrieve and summarize sensitive enterprise information. Organizations concerned about exposure in similar AI-integrated environments can run a privacy checkup to audit how broadly their assistant tools are configured, and security teams should verify credential strength across integrated platforms to limit downstream risk.
Atlassian confirmed the flaw was patched prior to public disclosure. The company issued a statement emphasizing that customer data security remains its highest priority. Varonis recommends that enterprises restrict which systems Rovo can reach, disconnect unused third-party integrations, segment sensitive areas such as legal, HR, and finance repositories, disable browsing and multistep automation features not in active use, and monitor assistant activity logs for anomalous behavior. Admins who want to verify whether connected accounts have already surfaced in known exposures can use an email breach checker as a baseline triage step while hardening their AI deployment posture.