Particle.news
Download on the App Store

Atlassian Fixes Rovo One-Click Prompt Injection as Upload Attack Path Remains Public

The disclosure highlights how an AI assistant with wide app access can turn a signed-in user’s account into a channel for leaking internal data.

Overview

  • Security firm Varonis disclosed a one-click URL-parameter flaw called RovoBlast that preloaded attacker instructions into a user’s Rovo chat and Atlassian deployed a server-side fix that Bugcrowd marked resolved on July 8, 2026.
  • PromptArmor published a separate content-borne prompt-injection chain on August 5, 2026 that hides instructions inside uploaded files so Rovo can collect data the signed-in user can access and send it to an attacker, and the public record does not confirm a fix for that chain.
  • The link-based RovoBlast worked by passing a rovoChatPrompt parameter into the chat window and the demonstrated exfiltration used Rovo’s ResearchAgent tool to autonomously gather internal results and fetch them to an attacker-controlled endpoint.
  • Rovo is enabled by default on Standard, Premium, and Enterprise plans and can reach Jira, Confluence, Bitbucket and many third-party connectors, so any data a signed-in user can access is within the assistant’s potential scope and admin controls have limits on shared site features.
  • Researchers and Atlassian report no evidence of real-world exploitation so far and recommend tightening connector permissions, disconnecting unused integrations, disabling browsing or autonomous agents when not needed, and monitoring assistant activity logs for suspicious requests.