RovoBlast: How One Click Triggered Atlassian's AI Assistant to Leak Data
Varonis, Friday, August 7th, 2026
Varonis Threat Labs discloses RovoBlast, a one-click prompt injection against Atlassian's Rovo AI assistant.
Varonis Threat Labs has uncovered a vulnerability in Rovo, Atlassian's enterprise AI assistant.
Dubbed RovoBlast, the attack requires only a single click on a link from the victim. That click triggers the attacker's embedded instructions, forcing Rovo to accept externally supplied parameters as trusted inputs within the user's session.
Because the assistant operates with the user's own access, the technique can be used to extract data the user can reach.