Atlassian Rovo Flaw Enabled Data Theft via Prompt Injection
A one-click prompt injection attack on Atlassian's Rovo could expose enterprise data across connected apps.
Researchers at DEF CON 34 demonstrated a critical vulnerability in Atlassian's enterprise AI assistant Rovo that could allow attackers to exfiltrate sensitive corporate data with a single click. The attack, dubbed "RovoBlast," exploited a prompt injection flaw in Rovo's chat interface to hijack the assistant's trusted position within enterprise environments.
One Click to Compromise
Varonis researcher Dolev Taler explained in a blog post that the attack uses Rovo's rovoChatPrompt parameter to inject attacker-controlled instructions directly into Rovo Chat. The crafted link, when clicked by a victim, forces Rovo to treat externally supplied parameters as trusted inputs within the user's session.
“A single click on a link triggers the attacker’s embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user’s session,”
This one-click interaction was sufficient to potentially grant attackers access to anything Rovo is privileged to see, according to Varonis.
Broad Access Amplifies Impact
Rovo is typically integrated across sensitive work environments, including Slack, Microsoft 365, and Google Workspace, giving it wide-reaching access to organizational data. Varonis found that Rovo could enumerate and search data across a broad range of sources, such as Jira, Confluence, Bitbucket, relational databases, uploaded files, webpages, and archives.
The researchers noted that Rovo connectors extend its reach to more than 50 platforms, meaning attackers could access data protected behind credentials without any compromise, all while appearing as legitimate assistant activity on behalf of the user.
Removal Not an Option
Complicating mitigation efforts, Taler noted that Rovo cannot be fully uninstalled from an environment. He emphasized that organizations attempting to remove the risk may not be able to eliminate Rovo's presence or its associated attack surface, making robust input validation and security controls even more critical.
Exfiltration Chain Demonstrated
Varonis researchers then tested whether Rovo's agent capabilities could turn that access into a full data-exfiltration path. They found that Rovo's ResearchAgent could perform deep, multi-source web research and navigate across websites through multiple autonomous steps.
In Varonis's testing, this created a potential chain where Rovo could retrieve information from internal sources and move it toward an external destination. Notably, the researchers did not need a jailbreak, double request, or complicated prompt-surgery attack; the single click on the crafted link was enough to seed the malicious instructions.
Once inside the session, Rovo's autonomous agent capabilities were shown to be capable of carrying out the entire attack. Taler added, “Rovo includes built-in automation that accelerates exfiltration once misused.”
Mitigation Beyond the Patch
Atlassian has since fixed the issue, which was reported through a bug bounty program on Bugcrowd. However, the company did not immediately respond to CSO's request for comments. Given the persistence of the attack surface, researchers advised measures beyond just applying the patch.
They recommended shrinking Rovo's blast radius by limiting connected systems, keeping highly sensitive areas such as legal, HR, finance, and incident response out of scope, and disabling browsing or multi-step automation that organizations do not need.
“The less the assistant can see, the less it can leak, regardless of prompt injection or agent abuse,” the researchers stated.
Part of a Broader AI Risk
Varonis drew parallels with other recently disclosed AI attacks like SearchLeak, EchoLeak, ShadowLeak, and Antigravity. The company said RovoBlast is another example of a broader AI security issue where “untrusted inputs, autonomous behavior, and trusted communication” are together creating serious data exposure.
Implications for Enterprises
This vulnerability underscores the growing risk that AI assistants, with their deep access to corporate data and autonomous capabilities, can become powerful attack vectors. The fact that a single click could lead to data exfiltration suggests that organizations must treat AI assistants as high-value targets.
While Atlassian has patched this specific flaw, the underlying issue of prompt injection and autonomous agent behavior remains. Enterprises using Rovo or similar tools should assess their connected systems and consider limiting the scope of AI access to sensitive data, as recommended by Varonis.
As AI integration becomes more pervasive, the attack surface expands, and the need for robust input validation and continuous monitoring becomes ever more critical.
Sources
- CSO Online Original source
- SearchLeak Also reporting
- EchoLeak Also reporting
- ShadowLeak Also reporting
- Antigravity Also reporting
Continue Reading
Hostile SIMs exploit spec-compliant commands
Malicious SIM cards can force phones to leak files, drop to 2G, or crash—by abusing standard SIM commands.
Gray to White: A Hacker's Redemption Arc
Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.
Cyber Prep Gap Leaves UK Factories Vulnerable
New Make UK report finds half of UK manufacturers lack a formal cyber incident response plan despite rising incidents.