Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a Single Click
Article excerpt
Highlighted: the sentence this signal was extracted from
RovoBlast is a recently disclosed vulnerability affecting Atlassian's Rovo AI assistant that allows attackers to expose sensitive enterprise data through a single malicious link. According to Varonis Threat Labs, the vulnerability exploits Rovo's handling of URL-supplied prompts, enabling attackers to inject malicious instructions into an authenticated user's AI session. The attack does not require traditional permission bypasses, jailbreaks, or exploits of the victim's account. Instead, it exploits a parameter-to-prompt (P2P) weakness: Rovo treats text embedded in a URL as a pre-filled chat instruction within a user's trusted session. Researchers named the issue RovoBlast due to the potentially extensive impact created by Rovo's integrations and agent capabilities. A crafted link using the `rovoChatPrompt` parameter could open Rovo Chat with attacker-provided instructions preloaded. An example link follows this pattern: When a logged-in employee clicks the link, Rovo may interpret the supplied content as an instruction rather than untrusted external input. Varonis indicated that this creates a low-friction pathway for attackers, allowing the assistant to search, summarize, and possibly move organizational data without obvious warnings or confirmation prompts. Rovo is designed to serve as an AI layer across Atlassian products, including Jira, Confluence, and Bitbucket. It...
Keep reading with a free account
The rest of this article, and every signal for Atlassian, is in your free account.
