Attackers Can Steal Enterprise Data with One Click Through Atlassian Rovo Flaw Varonis Threat Labs disclosed a vulnerability in Atlassian's Rovo AI assistant, dubbed RovoBlast, that allows attackers to steal enterprise data with a single click via a parameter-to-prompt injection in the rovoChatPrompt parameter. The flaw exploits Rovo's integration with Jira, Confluence, Bitbucket, Slack, Microsoft 365, and Google Workspace, enabling unauthorized data access without bypassing permissions. A newly disclosed security flaw in Atlassian’s Rovo AI assistant is raising alarms across the cybersecurity community, and for good reason. Dubbed RovoBlast, the vulnerability allows attackers https://www.kobaran.com/tag/Attackers to hijack a trusted employee’s AI session using nothing more than a single crafted link, no stolen passwords, no malware downloads, and no obvious red flags for the person who clicks it. The discovery, made by researchers at Varonis Threat Labs, lands at a moment when enterprises are racing to embed AI assistants deep into their daily workflows. Tools like Rovo promise faster research, smarter summaries, and seamless access across platforms such as Jira, Confluence, Bitbucket, Slack, Microsoft 365, and Google Workspace. That same breadth of access, researchers warn, is exactly what makes RovoBlast so dangerous. For security teams, the flaw is a reminder that AI adoption is outpacing AI governance in many organizations. As companies grant these assistants broader permissions to boost productivity, attackers are already probing for the seams. RovoBlast may be one of the clearest examples yet of how a single click can quietly turn a helpful AI tool into a data exfiltration pipeline. What Is the RovoBlast Vulnerability How the Exploit Works RovoBlast does not rely on jailbreaking Rovo or bypassing an employee’s account permissions. Instead, Varonis says it exploits what researchers call a parameter-to-prompt, or P2P, weakness. In plain terms, Rovo treats text embedded inside a URL as a legitimate, pre-filled chat instruction rather than as untrusted input from an outside source. Attackers can build a malicious link using the rovoChatPrompt parameter to preload attacker-written instructions directly into Rovo Chat. A link following this pattern illustrates the mechanism: https://home.atlassian.com/chat?rovoChatPathway=chat&rovoChatPrompt=