A newly discovered vulnerability in Atlassian's Rovo enterprise AI assistant allows attackers to turn a single malicious link into a route for exposing sensitive corporate data, known as RovoBlast by Varonis Threat Labs This article explores vulnerability atlassian rovo. . The flaw exploits how the chatbot handles externally supplied URL parameters when a logged-in employee clicks on a crafted link.
When an attacker-controlled text is inserted into Rovo's chat interface and then executed within the victim's authenticated session, it inherits their existing access to company resources. The Rovo rovoChatPrompt parameter allowed for the inclusion of a link to open Rovo Chat with pre-filled instructions, effectively creating a low-friction prompt-injection vulnerability: users didn't need to copy text, upload documents, grant new permissions, or explicitly approve actions.
Varonis reported that the affected behavior lacked prominent warnings, confirmation dialogs, or indicators indicating the prompts originated from an untrusted external parameter. The agent supports multi-step research and web navigation, which could transform a simple retrieval request into a broader sequence of data collection, transformation, and external transmission. Mitigation Organizations using Rovo should limit their assistant’s available data scope by disconnecting unused integrations and restricting access to high-sensitivity repositories like legal, HR, finance, and incident-response content.
Security teams should also disable unnecessary agent functions, particularly browsing and multi-step automation, while monitoring AI activity for unusual searches, runs, or cross-platform access patterns.












