RovoBlast: Critical Atlassian Rovo AI Vulnerability Exposes Enterprise Data via Malicious Links
Security researchers at Varonis Threat Labs have uncovered RovoBlast, a severe vulnerability in Atlassian’s Rovo AI assistant that enables attackers to extract sensitive enterprise data through a single malicious link. The flaw exploits Rovo’s handling of URL-supplied prompts, allowing threat actors to inject malicious instructions into an authenticated user’s AI session without requiring account compromise or permission bypasses.
The attack leverages a parameter-to-prompt (P2P) weakness, where Rovo treats text embedded in a URL (via the rovoChatPrompt parameter) as a pre-filled chat instruction within a trusted session. A crafted link such as https://home.atlassian.com/chat?rovoChatPathway=chat&rovoChatPrompt=<malicious_prompt> can trigger the assistant to execute attacker-controlled commands when clicked by a logged-in user.
Rovo, designed as an AI layer across Atlassian products (Jira, Confluence, Bitbucket) and external platforms (Slack, Microsoft 365, Google Workspace, databases, and web resources), operates under the permissions of the authenticated user. This means malicious prompts can search, summarize, or exfiltrate data while appearing as legitimate AI-assisted workflows. The ResearchAgent feature is particularly concerning, as it can perform multi-step research, navigate websites, and potentially chain actions to retrieve and transmit sensitive information all from a single prompt.
Unlike traditional prompt-injection attacks, RovoBlast does not require elaborate jailbreaks or repeated inputs, making it harder for defenders to detect. The vulnerability underscores the risks of AI assistants processing untrusted content while holding broad data access. Organizations are advised to restrict Rovo’s integrations, disable unnecessary automation features, and monitor AI logs for unusual behavior to mitigate exposure. The discovery highlights a growing security challenge: AI assistants with expansive permissions and external connectivity can become low-friction vectors for data exfiltration.
Source: https://gbhackers.com/atlassian-rovo-ai-vulnerability/
Atlassian TPRM report: https://www.rankiteo.com/company/atlassian
"id": "atl1786359965",
"linkid": "atlassian",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Enterprises using Atlassian '
'Rovo AI assistant',
'industry': 'Software (Enterprise Collaboration & AI)',
'name': 'Atlassian',
'type': 'Technology Company'}],
'attack_vector': 'Malicious Link (URL-based prompt injection)',
'data_breach': {'data_exfiltration': 'Yes (via malicious prompts)',
'sensitivity_of_data': 'High (potentially confidential '
'business data)',
'type_of_data_compromised': 'Sensitive enterprise data'},
'description': 'Security researchers at Varonis Threat Labs have uncovered '
'RovoBlast, a severe vulnerability in Atlassian’s Rovo AI '
'assistant that enables attackers to extract sensitive '
'enterprise data through a single malicious link. The flaw '
'exploits Rovo’s handling of URL-supplied prompts, allowing '
'threat actors to inject malicious instructions into an '
'authenticated user’s AI session without requiring account '
'compromise or permission bypasses. The attack leverages a '
'parameter-to-prompt (P2P) weakness, where Rovo treats text '
'embedded in a URL (via the rovoChatPrompt parameter) as a '
'pre-filled chat instruction within a trusted session. A '
'crafted link can trigger the assistant to execute '
'attacker-controlled commands when clicked by a logged-in '
'user. Rovo, designed as an AI layer across Atlassian products '
'(Jira, Confluence, Bitbucket) and external platforms (Slack, '
'Microsoft 365, Google Workspace, databases, and web '
'resources), operates under the permissions of the '
'authenticated user. This means malicious prompts can search, '
'summarize, or exfiltrate data while appearing as legitimate '
'AI-assisted workflows. The ResearchAgent feature is '
'particularly concerning, as it can perform multi-step '
'research, navigate websites, and potentially chain actions to '
'retrieve and transmit sensitive information all from a single '
'prompt.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'AI-driven data exposure',
'data_compromised': 'Sensitive enterprise data',
'operational_impact': 'Data exfiltration via AI-assisted workflows',
'systems_affected': ['Atlassian Rovo AI assistant',
'Jira',
'Confluence',
'Bitbucket',
'Slack',
'Microsoft 365',
'Google Workspace',
'Databases',
'Web resources']},
'lessons_learned': 'The vulnerability underscores the risks of AI assistants '
'processing untrusted content while holding broad data '
'access. AI assistants with expansive permissions and '
'external connectivity can become low-friction vectors for '
'data exfiltration.',
'post_incident_analysis': {'root_causes': 'Parameter-to-Prompt (P2P) weakness '
'in Atlassian Rovo AI assistant '
'allowing URL-based prompt '
'injection'},
'recommendations': ['Restrict Rovo’s integrations',
'Disable unnecessary automation features',
'Monitor AI logs for unusual behavior'],
'references': [{'source': 'Varonis Threat Labs'}],
'response': {'containment_measures': ['Restrict Rovo’s integrations',
'Disable unnecessary automation '
'features'],
'enhanced_monitoring': ['Monitor AI logs for unusual behavior'],
'third_party_assistance': 'Varonis Threat Labs (security '
'researchers)'},
'title': 'RovoBlast: Critical Atlassian Rovo AI Vulnerability Exposes '
'Enterprise Data via Malicious Links',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'Parameter-to-Prompt (P2P) weakness in Atlassian '
'Rovo AI assistant (rovoChatPrompt parameter)'}