I
Agentic Intelligence · Infomly

One click on a link just handed an attacker your entire Jira. Atlassian Rovo can't be uninstalled.

AI-Assisted Content — Produced with AI assistance and human editorial review. Learn more
Atlassian's enterprise AI assistant Rovo had a vulnerability disclosed at DEF CON 34 last week.

Varonis called it RovoBlast. One click on a crafted link.

No jailbreak. No permission bypass. No warning to the user.

The attacker's instructions land directly inside your authenticated AI session. Rovo treats externally supplied URL parameters as trusted input.

Here's what makes this different from every other AI vulnerability:

Rovo connects to Jira, Confluence, Bitbucket, Slack, Microsoft 365, Google Workspace, and over 50 more platforms through connectors.

One seeded prompt told Rovo to list everything it could see. The answer included relational databases, uploaded files, web pages, and archived content.

Then there's ResearchAgent. Rovo's built-in autonomous tool that can conduct multi-source web research and navigate across arbitrary websites.

Once an attacker's prompt was seeded, ResearchAgent pulled internal data and pushed it to the open web in a single automated chain. Zero user interaction beyond the initial click.

Three proof-of-concept scenarios worked: exfiltrating Confluence pages, Jira tickets, and SharePoint content containing personal data.

Atlassian patched the URL parameter issue. But here's the part that should alarm every CISO:

Rovo cannot be fully uninstalled. Organizations cannot remove the risk or the attack surface.

And there's a second vulnerability. PromptArmor disclosed an unpatched flaw on August 5. Hidden text in a PDF. Rovo processes the file, follows embedded instructions, and sends internal data to an attacker's server.

Atlassian acknowledged it in May. Still no fix. Still no response to follow-ups.

Your AI assistant has access, autonomy, and a communication path to the outside world. That's the lethal trifecta.

Audit every AI assistant connected to your knowledge base today. Limit integrations. Disable autonomous agents. Treat external prompts as hostile input.
💬 Consultation · Got questions? Talk to an expert →
Enterprise AI Impact — filtered for signal, not noise The AI briefing CTOs read before their morning meeting 3 minutes. Zero fluff. Only what moves the needle. $5/mo — your cheapest competitive edge
Subscribe — $5/mo

0 Comments

No comments yet. Be the first.