RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data Varonis Threat Labs disclosed a vulnerability in Atlassian's Rovo AI assistant, dubbed RovoBlast, where a single click on a crafted link can trigger attacker-embedded instructions and force Rovo to accept externally supplied parameters as trusted inputs, enabling data exfiltration without jailbreaks or permission bypass. The flaw, fixed by Atlassian and published via Bug Crowd, was presented at DEF CON 34, and it affects Rovo's integration across Jira, Confluence, Bitbucket, Slack, Microsoft 365, and Google, with autonomous agents amplifying the risk. Varonis Threat Labs uncovered a vulnerability in Rovo, Atlassian's enterprise AI assistant. Dubbed RovoBlast, a single click on a link triggers the attacker's embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user's session. No jailbreaks, no permission bypass, and no warnings or confirmation. The same capabilities that make Rovo a powerful tool also make RovoBlast especially dangerous. Rovo operates as an AI layer across the core products in the Atlassian platform, including Jira, Confluence, Bitbucket, as well as other connected SaaS tools like Slack, Microsoft 365, and Google. Atlassian also features autonomous-agent capabilities that can carry out multi-step actions without user involvement. When AI can search, connect, and act across business systems, the blast radius of a mistake or attack grows significantly, a risk that CISOs and security teams are increasingly concerned about. Rovo operates within the trust boundary that security teams rely on to enforce controls, visibility, and accountability. Actions executed under a legitimate user identity inherit existing access and blend into normal AI-assisted workflows, leaving little to distinguish abuse from routine use. We responsibly disclosed RovoBlast to Atlassian https://bugcrowd.com/disclosures/bf1922fb-99d0-4d3b-b419-1728720d29ec/one-click-data-exfiltration-via-rovochatprompt-url-parameter-confluence-rovo , which was fixed and published via Crowd Source in Bug Crowd, then debuted at DEF CON 34. Continue reading to discover how combining trusted input, broad data access, and built-in automations create a low-friction path to organizational data exposure. Meet Rovo Atlassian's Rovo is an "AI teammate" that unifies search, chat, and agent actions across Jira, Confluence, and connected SaaS apps. It's powered by Atlassian's Teamwork Graph and a growing set of connectors and agent capabilities. Rovo's value comes from context: federated search across Atlassian and third-party tools, conversational answers in Rovo Chat, and task-taking Rovo Agents. The capabilities that make Rovo helpful also create an expansive attack surface if external inputs aren't treated as untrusted throughout execution. Parameter to Prompt strikes again In January 2026, Varonis Threat Labs uncovered Reprompt in Copilot https://www.varonis.com/blog/reprompt?hsLang=en , showing how a single click on a crafted link could turn a benign URL parameter into a Parameter-to-Prompt P2P pathway that executes inside the user's trusted AI session. RovoBlast presents a similar opportunity. Like other AI assistants, Rovo accepts externally supplied parameters that run automatically, meaning a link is infused with data and instructions. Rovo uses the "rovoChatPrompt" parameter to inject content directly into its chat entry. For example, Rovo's chat entry can be invoked with a route and a pre-filled prompt via the following pattern: https://home.atlassian.com/chat?rovoChatPathway=chat&rovoChatPrompt=