VARONIS Threat Labs has revealed a critical vulnerability in Atlassian's enterprise AI assistant, Rovo, called RovoBlast. This flaw allows attackers to inject harmful instructions into a user's live AI session via a specially crafted link, exploiting the assistant's acceptance of external input. Rovo integrates across platforms like Jira and Confluence, providing autonomous task features that facilitated the attack.
The vulnerability was linked to the _rovoChatPrompt_ URL parameter, enabling data exfiltration from various tools including Jira and SharePoint. Varonis presented their findings at DEF CON 34, and Atlassian has addressed the issue with a fix. Recommendations for preventing similar attacks include limiting Rovo's access to sensitive data and disabling unused features.