Risk of enterprise data leakage from "one-click" vulnerability on Atlassian Rovo AI
- Thảo Nguyên

- 7 days ago
- 3 min read
Deploying artificial intelligence (AI) assistants into workflows significantly boosts productivity, but it also introduces critical cybersecurity risks that cannot be ignored. The discovery of RovoBlast - a severe security vulnerability in the Atlassian Rovo AI assistant serves as proof that an enterprise's internal data can be exfiltrated through a single malicious link.
RovoBlast: A one-click vulnerability threatening enterprise data
At the DEF CON 34 security conference, researchers from Varonis Threat Labs disclosed details about RovoBlast. This is a "one-click" vulnerability, meaning an attacker only needs to trick a user into clicking a specifically crafted link.
As soon as the link is opened, pre-crafted malicious instructions are injected directly into the victim's active AI session. Notably, this attack does not require jailbreaking or bypassing access controls, as the Rovo assistant inherently treats external parameters as trusted input.
The "Parameter-to-prompt injection" attack mechanism
The technique leveraged by RovoBlast is known as Parameter-to-Prompt Injection (P2P) - a method similar to the Reprompt vulnerability previously discovered in Microsoft Copilot.
Attackers exploit a URL parameter named rovoChatPrompt to pre-populate malicious content into Rovo's chat window. Researchers discovered that even if the organization ID parameter in the URL is left blank, Atlassian's system automatically routes the request to the victim's default workspace. The entire process occurs silently, displaying no alerts to inform users that their AI session has been compromised.
Data exfiltration via AI autonomous tools
As an enterprise AI assistant, Rovo is deeply integrated with various systems, including Jira, Confluence, Bitbucket, Slack, Microsoft 365, Google Workspace, databases, uploaded files, and document archives. It features autonomous capabilities (agentic features) that allow it to execute multi-step workflows without requiring human intervention.
This very autonomy becomes the exploitable flaw. Rovo features a built-in tool called ResearchAgent, tasked with automatically searching for information and browsing the web. When the malicious link triggers the injected prompt, Rovo automatically retrieves sensitive internal information and exfiltrates it to external public websites.
In proof-of-concept (PoC) testing, the research team demonstrated that a single malicious link was sufficient for Rovo to automatically collect and exfiltrate data from:
Confluence document pages.
Jira tickets.
SharePoint content containing personally identifiable information (PII).
Mitigation measures and advice from IPSIP Vietnam experts
Varonis fully disclosed RovoBlast to Atlassian, and the technology company released a patch resolving the vulnerability prior to public disclosure. The technical details of the research have also been published on Varonis's blog.
However, this incident serves as a wake-up call for all organizations deploying AI. Although this specific vulnerability has been patched, the risk of prompt injection in virtual assistants remains a constant threat. To reinforce information security, experts from IPSIP Vietnam recommend establishing a defense-in-depth strategy.

Privileged Access Management (PAM): AI assistants should not be given unrestricted access to every corner of the system. Enterprises must enforce the principle of Least Privilege. Through Privileged Access Management (PAM/BASTION) solutions provided by IPSIP, organizations can strictly control what the AI can interact with, neutralizing the risk of AI being exploited for unauthorized data exfiltration.
Segmenting sensitive data areas: Critical departments such as Legal, HR, and Finance should be completely isolated from the AI system's indexing scope. IPSIP experts assist enterprises in assessing infrastructure to perform secure network segmentation, combined with internal data encryption to neutralize exfiltration attempts even if the AI is manipulated.
Risk testing and disabling redundant autonomous features: Allowing AI to freely browse the web or perform multi-step automated tasks unintentionally expands the attack surface. In addition to disabling rarely used features, organizations should periodically utilize Penetration Testing (Pentest) and Vulnerability Scanning services from IPSIP to proactively discover vulnerabilities in AI-integrated systems before threat actors can exploit them.
Continuous cybersecurity monitoring (24/7 SOC): P2P vulnerabilities like RovoBlast are exceptionally dangerous because they occur silently without generating user alerts. Manual log monitoring alone is insufficient. With a 24/7 SOC system combining XDR/NDR technologies from IPSIP Vietnam, any abnormal data retrieval, aggregation, or exfiltration from an AI session will be detected and blocked in real-time by artificial intelligence and security engineers.
The RovoBlast incident highlights the fine line between automation convenience and information security risks. Strictly controlling the operational scope of AI assistants, combined with deep security solutions from an experienced partner like IPSIP Vietnam, enables enterprises to confidently leverage technological power while ensuring absolute protection for their data assets.












Comments