Atlassian patched a critical flaw in its Rovo enterprise AI assistant that could let a single malicious link plant attacker instructions into a user’s live AI session and exfiltrate company data. Varonis calls the technique 'RovoBlast' and says it abused the rovoChatPrompt URL parameter and default organization routing, with no CVE listed in this report. The issue affected Rovo’s access to Atlassian apps and connected services including Microsoft 365, Google Workspace, Slack, and SharePoint, and could trigger autonomous multi-step data retrieval through Rovo’s ResearchAgent.
Why it matters: Organizations using Rovo could have had sensitive internal documents and tickets pulled out through a one-click phishing-style link, so administrators should review Rovo integrations, restrict access to sensitive systems, and monitor AI assistant activity. The flaw is already fixed, but the story matters because it shows how connected AI assistants can turn one user action into broad enterprise data exposure.
Eduard Kovacs
2026.08.08
100% relevant
This article is the initial disclosure of the RovoBlast vulnerability and Atlassian's fix, establishing a distinct enterprise AI data-exposure event not listed among existing tracked stories.
← Back to all stories