DEF CON — Varonis Risk Labs has disclosed a one-click vulnerability in Rovo, Atlassian’s enterprise AI assistant, that permit a specifically crafted hyperlink seed attacker-controlled directions straight right into a person’s dwell AI session.
Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, counting on the truth that the assistant merely handled externally provided parameters as trusted enter.
Rovo capabilities as an AI layer spanning Jira, Confluence, Bitbucket, and third-party instruments equivalent to Slack, Microsoft 365, and Google Workspace. It additionally carries autonomous agent options able to finishing multi-step duties with no additional person involvement, which is what enabled the RovoBlast assault.
[ Read: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones ]
The exploit leveraged a URL parameter known as rovoChatPrompt, which pre-fills content material straight into Rovo’s chat window. Varonis researchers describe this assault path as parameter-to-prompt (P2P) injection, which they beforehand reported in Microsoft Copilot as Reprompt in January.
Researchers seen that the group ID a part of the URL could possibly be left clean and Atlassian would nonetheless route the request into the sufferer’s personal default group, all with none warning or indicator that the session had been seeded by an outdoor supply.
To gauge the potential blast radius, the researchers merely requested Rovo what knowledge it might see. The AI’s reply included Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded information, internet pages, and archived content material.
The precise leakage got here from ResearchAgent, certainly one of Rovo’s built-in instruments, which may autonomously conduct multi-source internet analysis and navigate throughout arbitrary websites. As soon as an attacker’s immediate was seeded via the malicious hyperlink, that very same functionality let Rovo pull inside knowledge and push it out to the open internet in a single automated chain.
The group demonstrated the approach in three separate proof-of-concept situations: exfiltrating Confluence pages, Jira tickets, and SharePoint content material containing private knowledge.
Notably, the researchers discovered {that a} single seeded hyperlink was typically sufficient to set off the leak. The assault didn’t require chaining a number of requests or any extra bypass steps to get Rovo to retrieve and summarize delicate knowledge.
Varonis disclosed RovoBlast to Atlassian, which mounted the difficulty earlier than the findings have been printed.
The researchers advocate that organizations restrict which techniques Rovo can attain, disconnect unused integrations, wall off delicate areas equivalent to authorized, HR, and finance, disable looking or multistep automation options that aren’t in lively use, and pair this with routine monitoring of assistant exercise logs.
Varonis introduced the analysis at DEF CON 34 on Friday. A technical write-up is on the market on the Varonis weblog.
*assertion from Atlassian eliminated at Atlassian’s request
Associated: Zero-Click on AI Browser Hacking: Claude and ChatGPT Atlas Hijacked by way of Emails, X Posts
Associated: Meta AI Hacked Exterior Methods Throughout Cybersecurity Testing
Associated: Atlassian, Splunk Patch Crucial Vulnerabilities







