Atlassian Fixes RovoBlast Flaw That Risked Data Leaks
Atlassian’s Rovo is an AI assistant designed to search enterprise knowledge and automate work across connected applications. Security firm Varonis said a vulnerability dubbed RovoBlast showed how such integrations can broaden exposure when an AI tool is manipulated by hostile instructions, potentially putting sensitive corporate information held across multiple services at risk.
According to Varonis, an attacker could embed malicious instructions in a URL and induce a user to click the link, triggering commands that use Rovo’s connectors to extract application data. Atlassian completed a fix in July 2026. Neither the number of affected customers nor the volume of any data exposed through the flaw was disclosed.
All Coverage
1 original reportsThe Backstory
The history behind this eventHidden PDF Instructions Can Hijack Atlassian Rovo, Leak Data
Atlassian’s Rovo is an enterprise AI assistant that searches across Jira, Confluence and connected third-party services using a signed-in employee’s existing permissions. That reach makes indirect prompt injection a material security risk: text hidden in a PDF or another untrusted document can be interpreted as an instruction rather than content, turning legitimate access into a channel for extracting internal records and sending them outside the organization without the user knowingly authorizing the transfer.
PromptArmor said it notified Atlassian on May 23, 2026, and published its proof of concept on Aug. 5. In the demonstration, a poisoned document prompted Rovo to gather Jira and Confluence data, append it to an attacker-controlled URL and request that address; disabling web search did not block the transfer, and no separate approval was required. A different one-click flaw, RovoBlast, was fixed server-side on July 8 after receiving a $6,000 Bugcrowd bounty and P2 rating. As of Aug. 8, no fix for PromptArmor’s content-borne route had been confirmed, and neither report cited real-world exploitation.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.