DEF CON — Varonis Menace Labs has disclosed a one-click vulnerability in Rovo, Atlassian’s enterprise AI assistant, that allow a specifically crafted hyperlink seed attacker-controlled directions immediately right into a person’s reside AI session.
Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, counting on the truth that the assistant merely handled externally provided parameters as trusted enter.
Rovo features as an AI layer spanning Jira, Confluence, Bitbucket, and third-party instruments reminiscent of Slack, Microsoft 365, and Google Workspace. It additionally carries autonomous agent options able to finishing multi-step duties with no additional person involvement, which is what enabled the RovoBlast assault.
[ Read: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones ]
The exploit leveraged a URL parameter known as rovoChatPrompt, which pre-fills content material straight into Rovo’s chat window. Varonis researchers describe this assault path as parameter-to-prompt (P2P) injection, which they beforehand reported in Microsoft Copilot as Reprompt in January.
Researchers observed that the group ID a part of the URL could possibly be left clean and Atlassian would nonetheless route the request into the sufferer’s personal default group, all with none warning or indicator that the session had been seeded by an outdoor supply.
To gauge the potential blast radius, the researchers merely requested Rovo what information it might see. The AI’s reply included Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded information, net pages, and archived content material.
The precise leakage got here from ResearchAgent, certainly one of Rovo’s built-in instruments, which might autonomously conduct multi-source net analysis and navigate throughout arbitrary websites. As soon as an attacker’s immediate was seeded by way of the malicious hyperlink, that very same functionality let Rovo pull inside information and push it out to the open net in a single automated chain.
The staff demonstrated the approach in three separate proof-of-concept eventualities: exfiltrating Confluence pages, Jira tickets, and SharePoint content material containing private information.
Notably, the researchers discovered {that a} single seeded hyperlink was typically sufficient to set off the leak. The assault didn’t require chaining a number of requests or any further bypass steps to get Rovo to retrieve and summarize delicate information.
Varonis disclosed RovoBlast to Atlassian, which fastened the difficulty earlier than the findings have been revealed.
The researchers suggest that organizations restrict which methods Rovo can attain, disconnect unused integrations, wall off delicate areas reminiscent of authorized, HR, and finance, disable looking or multistep automation options that aren’t in energetic use, and pair this with routine monitoring of assistant exercise logs.
An Atlassian spokesperson offered the next assertion to SecurityWeek:
The safety of our clients’ information is our highest precedence. We’re working with clients to implement protecting controls on their situations. That is an ongoing and evolving accountability, and we’re actively engaged on and investing in further options.
For the vulnerability to be exploited, a person with entry to a buyer’s Atlassian occasion should present untrusted content material with a immediate injection to Rovo. This can be a class of assault that impacts AI methods throughout the business. Much like any phishing-type assault, we suggest clients observe safety greatest practices and confirm that any content material offered to their Atlassian apps comes from a trusted supply.
Varonis introduced the analysis at DEF CON 34 on Friday. A technical write-up is offered on the Varonis weblog.
Associated: Zero-Click on AI Browser Hacking: Claude and ChatGPT Atlas Hijacked through Emails, X Posts
Associated: Meta AI Hacked Exterior Programs Throughout Cybersecurity Testing
Associated: Atlassian, Splunk Patch Vital Vulnerabilities










