cd /news/ai-safety/one-click-flaw-in-atlassian-rovo-exp… · home topics ai-safety article
[ARTICLE · art-90323] src=csoonline.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack

At DEF CON 34, Varonis researchers demonstrated a one-click prompt injection attack, dubbed RovoBlast, against Atlassian's enterprise AI assistant Rovo, which could expose sensitive data across connected platforms including Slack, Microsoft 365, and Google Workspace. The attack exploited the rovoChatPrompt parameter to inject attacker-controlled instructions, and Atlassian has since fixed the issue via a Bugcrowd bug bounty program. Varonis advised organizations to limit Rovo's connected systems and disable unneeded automation to reduce risk.

read3 min views1 publishedAug 10, 2026

Atlassian’s enterprise AI assistant Rovo, which is usually connected across sensitive work environments like Slack, Microsoft 365, and Google Workspace, was found vulnerable to data leaks through malicious instructions.

At DEF CON 34, researchers from Varonis demonstrated an attack that used Rovo’s rovoChatPrompt parameter to place attacker-controlled instructions directly into Rovo Chat.

“A single click on a link triggers the attacker’s embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user’s session,” Varonis researcher Dolev Taler said in a blog post, dubbing the attack “RovoBlast.”

The attack only required one click by the victim on a specially crafted link, which then allowed the attacker to potentially access anything Rovo is privileged.

The issue was reported to Atlassian through a bug bounty program hosted on Bugcrowd, and the company has since fixed it. The company, however, did not immediately respond to CSO’s request for comments.

Varonis found that Rovo could enumerate and search data across a wide range of sources available to an organization, including Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded files, webpages, and archives.

Rovo connectors extend reach to more than 50 platforms, Varonis said. Attackers could access data protected behind credentials without a compromise. This could all look like legitimate activity performed by the assistant on behalf of a user.

Taler also noted that Rovo cannot be fully uninstalled.

“Organizations attempting to remove the risk may not be able to eliminate Rovo’s presence in their environment or the associated attack surface, making robust input validation and security controls even more critical,” he said.

Varonis researchers then looked at whether Rovo’s agent capabilities could turn the access to corporate information into an actual data-exfiltration path.

They found that they could.

Rovo’s “ResearchAgent,” it turned out, could perform deep, multi-source web research and navigate across websites through multiple autonomous steps. In Varonis’ testing, that created a potential chain in which Rovo could retrieve information from internal sources and move it toward an external destination.

Importantly, the researchers said they did not need a jailbreak, a double request technique, or a complicated prompt-surgery attack. The single culprit clicking on the crafted Rovo link was enough to seed the malicious instructions.

Once inside the session, autonomous agent capabilities were shown to be capable of carrying out the attack in its entirety. “Rovo includes built-in automation that accelerates exfiltration once misused,” Taler added.

As the threat extended from a failing AI guardrail to the risk of automated damage escalation, researchers advised measures beyond a patch.

They recommended shrinking Rovo’s blast radius by limiting connected systems, keeping highly sensitive areas such as legal, HR, finance, and incident response out of scope, and disabling browsing or multi-step automation that organizations do not need.

“The less the assistant can see, the less it can leak, regardless of prompt injection or agent abuse,” they said.

Varonis drew parallels with other recently disclosed AI attacks like SearchLeak, EchoLeak, ShadowLeak, and Antigravity. The company said RovoBlast is just another example of a broader AI security issue where “untrusted inputs, autonomous behavior, and trusted communication” are together creating serious data exposure.

── more in #ai-safety 4 stories · sorted by recency
── more on @atlassian 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/one-click-flaw-in-at…] indexed:0 read:3min 2026-08-10 ·