Overview
- Security firm Varonis disclosed a one-click URL-parameter flaw called RovoBlast that preloaded attacker instructions into a user’s Rovo chat and Atlassian deployed a server-side fix that Bugcrowd marked resolved on July 8, 2026.
- PromptArmor published a separate content-borne prompt-injection chain on August 5, 2026 that hides instructions inside uploaded files so Rovo can collect data the signed-in user can access and send it to an attacker, and the public record does not confirm a fix for that chain.
- The link-based RovoBlast worked by passing a rovoChatPrompt parameter into the chat window and the demonstrated exfiltration used Rovo’s ResearchAgent tool to autonomously gather internal results and fetch them to an attacker-controlled endpoint.
- Rovo is enabled by default on Standard, Premium, and Enterprise plans and can reach Jira, Confluence, Bitbucket and many third-party connectors, so any data a signed-in user can access is within the assistant’s potential scope and admin controls have limits on shared site features.
- Researchers and Atlassian report no evidence of real-world exploitation so far and recommend tightening connector permissions, disconnecting unused integrations, disabling browsing or autonomous agents when not needed, and monitoring assistant activity logs for suspicious requests.