{"slug": "one-click-flaw-in-atlassian-rovo-exposed-enterprise-data-via-prompt-injection", "title": "One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack", "summary": "At DEF CON 34, Varonis researchers demonstrated a one-click prompt injection attack, dubbed RovoBlast, against Atlassian's enterprise AI assistant Rovo, which could expose sensitive data across connected platforms including Slack, Microsoft 365, and Google Workspace. The attack exploited the rovoChatPrompt parameter to inject attacker-controlled instructions, and Atlassian has since fixed the issue via a Bugcrowd bug bounty program. Varonis advised organizations to limit Rovo's connected systems and disable unneeded automation to reduce risk.", "body_md": "Atlassian’s enterprise AI assistant Rovo, which is usually connected across sensitive work environments like Slack, Microsoft 365, and Google Workspace, was found vulnerable to data leaks through malicious instructions.\n\nAt [DEF CON 34](https://defcon.org), researchers from Varonis demonstrated an attack that used Rovo’s rovoChatPrompt parameter to place attacker-controlled instructions directly into Rovo Chat.\n\n“A single click on a link triggers the attacker’s embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user’s session,” Varonis researcher Dolev Taler said in a blog [post](https://www.varonis.com/blog/rovoblast), dubbing the attack “RovoBlast.”\n\nThe attack only required one click by the victim on a specially crafted link, which then allowed the attacker to potentially access anything Rovo is privileged.\n\nThe issue was reported to Atlassian through a bug bounty program hosted on Bugcrowd, and the company has since [fixed](https://bugcrowd.com/disclosures/bf1922fb-99d0-4d3b-b419-1728720d29ec/one-click-data-exfiltration-via-rovochatprompt-url-parameter-confluence-rovo) it. The company, however, did not immediately respond to CSO’s request for comments.\n\nVaronis found that Rovo could enumerate and search data across a wide range of sources available to an organization, including Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded files, webpages, and archives.\n\nRovo connectors extend reach to more than 50 platforms, Varonis said. Attackers could access data protected behind credentials without a compromise. This could all look like legitimate activity performed by the assistant on behalf of a user.\n\nTaler also noted that Rovo cannot be fully uninstalled.\n\n“Organizations attempting to remove the risk may not be able to eliminate Rovo’s presence in their environment or the associated attack surface, making robust input validation and security controls even more critical,” he said.\n\nVaronis researchers then looked at whether Rovo’s agent capabilities could turn the access to corporate information into an actual data-exfiltration path.\n\nThey found that they could.\n\nRovo’s “ResearchAgent,” it turned out, could perform deep, multi-source web research and navigate across websites through multiple autonomous steps. In Varonis’ testing, that created a potential chain in which Rovo could retrieve information from internal sources and move it toward an external destination.\n\nImportantly, the researchers said they did not need a jailbreak, a double request technique, or a complicated prompt-surgery attack. The single culprit clicking on the crafted Rovo link was enough to seed the malicious instructions.\n\nOnce inside the session, autonomous agent capabilities were shown to be capable of carrying out the attack in its entirety. “Rovo includes built-in automation that accelerates exfiltration once misused,” Taler added.\n\nAs the threat extended from a failing AI guardrail to the risk of automated damage escalation, researchers advised measures beyond a patch.\n\nThey recommended shrinking Rovo’s blast radius by limiting connected systems, keeping highly sensitive areas such as legal, HR, finance, and incident response out of scope, and disabling browsing or multi-step automation that organizations do not need.\n\n“The less the assistant can see, the less it can leak, regardless of prompt injection or agent abuse,” they said.\n\nVaronis drew parallels with other recently disclosed AI attacks like [SearchLeak](https://www.csoonline.com/article/4186970/m365-copilot-searchleak-your-prompt-injection-attack-surface-just-got-bigger.html), [EchoLeak](https://www.csoonline.com/article/4068175/gemini-trifecta-ai-autonomy-without-guardrails-opens-new-attack-surface.html), [ShadowLeak](https://www.csoonline.com/article/4059606/meet-shadowleak-impossible-to-detect-data-theft-using-ai.html), and [Antigravity](https://www.csoonline.com/article/4161382/prompt-injection-turned-googles-antigravity-file-search-into-rce.html). The company said RovoBlast is just another example of a broader AI security issue where “untrusted inputs, autonomous behavior, and trusted communication” are together creating serious data exposure.", "url": "https://wpnews.pro/news/one-click-flaw-in-atlassian-rovo-exposed-enterprise-data-via-prompt-injection", "canonical_source": "https://www.csoonline.com/article/4207306/one-click-flaw-in-atlassian-rovo-exposed-enterprise-data-via-prompt-injection-attack.html", "published_at": "2026-08-10 11:59:41+00:00", "updated_at": "2026-08-10 12:09:11.463337+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-agents", "generative-ai"], "entities": ["Atlassian", "Rovo", "Varonis", "Dolev Taler", "DEF CON 34", "Bugcrowd", "Slack", "Microsoft 365"], "alternates": {"html": "https://wpnews.pro/news/one-click-flaw-in-atlassian-rovo-exposed-enterprise-data-via-prompt-injection", "markdown": "https://wpnews.pro/news/one-click-flaw-in-atlassian-rovo-exposed-enterprise-data-via-prompt-injection.md", "text": "https://wpnews.pro/news/one-click-flaw-in-atlassian-rovo-exposed-enterprise-data-via-prompt-injection.txt", "jsonld": "https://wpnews.pro/news/one-click-flaw-in-atlassian-rovo-exposed-enterprise-data-via-prompt-injection.jsonld"}}