Atlassian Rovo AI Flaw Could Have Exposed Jira, Confluence and SharePoint Data
Researchers have disclosed a one-click attack technique that could have caused Atlassian’s Rovo enterprise AI assistant to retrieve and disclose sensitive information from connected business systems....
Researchers have disclosed a one-click attack technique that could have caused Atlassian’s Rovo enterprise AI assistant to retrieve and disclose sensitive information from connected business systems. The issue, named RovoBlast by Varonis Threat Labs, was fixed by Atlassian before the research was published.
Rovo is integrated with Atlassian products including Jira, Confluence and Bitbucket, as well as external services such as Slack, Microsoft 365 and Google Workspace. Its agent capabilities can perform multistep tasks with limited additional user interaction, increasing the potential impact of an instruction-injection attack.
Malicious links seeded instructions
The attack relied on a URL parameter called rovoChatPrompt, which automatically inserted attacker-controlled text into Rovo’s chat interface when a user opened a specially crafted link. Varonis described the technique as parameter-to-prompt injection, a category of attack in which application parameters are treated as trusted instructions by an AI system.
According to the researchers, the link did not need to specify an organization identifier. Rovo could instead route the request to the victim’s default organization, without clearly indicating that the chat session had been pre-populated by external content. The researchers said the method did not require a jailbreak or a separate authorization bypass.
Testing showed that Rovo could identify information available through numerous connected sources, including internal project data, uploaded files, databases and archived content. Varonis said the ResearchAgent tool was particularly significant because it could conduct web research and move information between sources. In demonstrations, a single seeded link was used to retrieve and expose Confluence pages, Jira issues and SharePoint material containing personal information.
Recommended safeguards
Varonis advised organizations to review Rovo’s integrations and restrict access to systems containing sensitive legal, human resources and financial data. Organizations should also disconnect unused services, disable browsing or autonomous multistep features where they are not necessary, and monitor AI assistant activity logs for unusual behavior.
Atlassian said protecting customer data remains a priority and that it is working with customers on protective controls and additional safeguards. The company also characterized prompt injection as an industry-wide AI security challenge and urged users to verify the source of content supplied to Atlassian applications.
