{"id":9080,"date":"2026-08-10T11:59:41","date_gmt":"2026-08-10T11:59:41","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9080"},"modified":"2026-08-10T11:59:41","modified_gmt":"2026-08-10T11:59:41","slug":"one-click-flaw-in-atlassian-rovo-exposed-enterprise-data-via-prompt-injection-attack","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9080","title":{"rendered":"One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Atlassian\u2019s enterprise AI assistant Rovo, which is usually connected across sensitive work environments like Slack, Microsoft 365, and Google Workspace, was found vulnerable to data leaks through malicious instructions.<\/p>\n<p class=\"wp-block-paragraph\">At <a href=\"https:\/\/defcon.org\/\" target=\"_blank\" rel=\"noopener\">DEF CON 34<\/a>, researchers from Varonis demonstrated an attack that used Rovo\u2019s rovoChatPrompt parameter to place attacker-controlled instructions directly into Rovo Chat.<\/p>\n<p class=\"wp-block-paragraph\">\u201cA single click on a link triggers the attacker\u2019s embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user\u2019s session,\u201d Varonis researcher Dolev Taler said in a blog <a href=\"https:\/\/www.varonis.com\/blog\/rovoblast\" target=\"_blank\" rel=\"noopener\">post<\/a>, dubbing the attack \u201cRovoBlast.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The attack only required one click by the victim on a specially crafted link, which then allowed the attacker to potentially access anything Rovo is privileged.<\/p>\n<p class=\"wp-block-paragraph\">The issue was reported to Atlassian through a bug bounty program hosted on Bugcrowd, and the company has since <a href=\"https:\/\/bugcrowd.com\/disclosures\/bf1922fb-99d0-4d3b-b419-1728720d29ec\/one-click-data-exfiltration-via-rovochatprompt-url-parameter-confluence-rovo\" target=\"_blank\" rel=\"noopener\">fixed<\/a> it. The company, however, did not immediately respond to CSO\u2019s request for comments.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Rovo\u2019s broad access made the click worse<\/h2>\n<p class=\"wp-block-paragraph\">Varonis found that Rovo could enumerate and search data across a wide range of sources available to an organization, including Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded files, webpages, and archives.<\/p>\n<p class=\"wp-block-paragraph\">Rovo connectors extend reach to more than 50 platforms, Varonis said. Attackers could access data protected behind credentials without a compromise. This could all look like legitimate activity performed by the assistant on behalf of a user.<\/p>\n<p class=\"wp-block-paragraph\">Taler also noted that Rovo cannot be fully uninstalled.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOrganizations attempting to remove the risk may not be able to eliminate Rovo\u2019s presence in their environment or the associated attack surface, making robust input validation and security controls even more critical,\u201d he said.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Exfiltration was possible<\/h2>\n<p class=\"wp-block-paragraph\">Varonis researchers then looked at whether Rovo\u2019s agent capabilities could turn the access to corporate information into an actual data-exfiltration path.<\/p>\n<p class=\"wp-block-paragraph\">They found that they could.<\/p>\n<p class=\"wp-block-paragraph\">Rovo\u2019s \u201cResearchAgent,\u201d it turned out, could perform deep, multi-source web research and navigate across websites through multiple autonomous steps. In Varonis\u2019 testing, that created a potential chain in which Rovo could retrieve information from internal sources and move it toward an external destination.<\/p>\n<p class=\"wp-block-paragraph\">Importantly, the researchers said they did not need a jailbreak, a double request technique, or a complicated prompt-surgery attack. The single culprit clicking on the crafted Rovo link was enough to seed the malicious instructions.<\/p>\n<p class=\"wp-block-paragraph\">Once inside the session, autonomous agent capabilities were shown to be capable of carrying out the attack in its entirety. \u201cRovo includes built-in automation that accelerates exfiltration once misused,\u201d Taler added.<\/p>\n<p class=\"wp-block-paragraph\">As the threat extended from a failing AI guardrail to the risk of automated damage escalation, researchers advised measures beyond a patch.<\/p>\n<p class=\"wp-block-paragraph\">They recommended shrinking Rovo\u2019s blast radius by limiting connected systems, keeping highly sensitive areas such as legal, HR, finance, and incident response out of scope, and disabling browsing or multi-step automation that organizations do not need.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe less the assistant can see, the less it can leak, regardless of prompt injection or agent abuse,\u201d they said.<\/p>\n<p class=\"wp-block-paragraph\">Varonis drew parallels with other recently disclosed AI attacks like <a href=\"https:\/\/www.csoonline.com\/article\/4186970\/m365-copilot-searchleak-your-prompt-injection-attack-surface-just-got-bigger.html\">SearchLeak<\/a>, <a href=\"https:\/\/www.csoonline.com\/article\/4068175\/gemini-trifecta-ai-autonomy-without-guardrails-opens-new-attack-surface.html\">EchoLeak<\/a>, <a href=\"https:\/\/www.csoonline.com\/article\/4059606\/meet-shadowleak-impossible-to-detect-data-theft-using-ai.html\">ShadowLeak<\/a>, and <a href=\"https:\/\/www.csoonline.com\/article\/4161382\/prompt-injection-turned-googles-antigravity-file-search-into-rce.html\">Antigravity<\/a>. The company said RovoBlast is just another example of a broader AI security issue where \u201cuntrusted inputs, autonomous behavior, and trusted communication\u201d are together creating serious data exposure.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Atlassian\u2019s enterprise AI assistant Rovo, which is usually connected across sensitive work environments like Slack, Microsoft 365, and Google Workspace, was found vulnerable to data leaks through malicious instructions. At DEF CON 34, researchers from Varonis demonstrated an attack that used Rovo\u2019s rovoChatPrompt parameter to place attacker-controlled instructions directly into Rovo Chat. \u201cA single click [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9081,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9080","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9080"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9080"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9080\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9081"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9080"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9080"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9080"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}