Varonis Threat Labs researchers identified RovoBlast, a vulnerability affecting Atlassian Rovo.
The flaw showed how a single crafted link could introduce attacker-controlled instructions into a user’s trusted AI session and potentially expose organizational data.
Researchers Dolev Taler and Mark Vaitsman presented the findings at DEF CON 34 after responsibly reporting the vulnerability to Atlassian, which subsequently addressed it.
RovoBlast highlights a broader security challenge for enterprise AI.
When assistants can access sensitive data and autonomously interact with multiple business systems, untrusted input can create risks that extend well beyond a conventional chatbot session.
Key takeaways of the Varonis RovoBlast research
- RovoBlast used a Parameter-to-Prompt (P2P) attack that allowed a crafted link to introduce attacker-controlled instructions into an authenticated Atlassian Rovo session.
- The attack did not require a traditional jailbreak or permission bypass, instead relying on the user’s existing access to retrieve information from connected enterprise systems.
- Rovo’s integrations and autonomous agent capabilities increased the potential blast radius, creating a path for sensitive data to be retrieved and potentially exposed with minimal user interaction.
- Organizations should limit AI permissions, integrations, and autonomous capabilities while treating external prompts as untrusted input and monitoring AI activity for signs of abuse.
How the RovoBlast attack worked
Atlassian Rovo is an enterprise AI assistant that provides search, conversational, and agent capabilities across Jira, Confluence, Bitbucket, and connected third-party services.
Researchers discovered that Rovo accepted externally supplied content through its rovoChatPrompt URL parameter.
A specially constructed link could therefore prepopulate Rovo Chat with attacker-controlled instructions when a logged-in user clicked it.
Varonis describes this technique as Parameter-to-Prompt (P2P), an attack pattern the company previously documented in its Reprompt research involving Microsoft Copilot.
RovoBlast was especially concerning because exploitation did not require a conventional jailbreak or permissions bypass.
According to the researchers, externally supplied instructions could enter the user’s authenticated Rovo session without meaningful warnings or confirmation that the prompt originated from an external parameter.
The user’s existing permissions then determined what information Rovo could retrieve.
Rovo’s integrations increased the potential blast radius
Rovo’s usefulness comes partly from its ability to search and synthesize information across enterprise systems. That same connectivity increased the potential impact of RovoBlast.
During testing, researchers found that Rovo could access data across Jira, Slack, Google Workspace, Microsoft 365, databases, uploaded files, and other connected resources.
Rovo Connectors can further expand that access to dozens of external services.
This creates an important distinction between AI prompt injection and more traditional application attacks.
An attacker may not need to compromise each underlying system individually if an AI assistant already has legitimate access to them on the user’s behalf.
Actions performed through an authenticated AI session can also resemble legitimate activity, potentially making malicious behavior more difficult to distinguish from normal AI-assisted workflows.
Autonomous agents created another path to data exposure
The researchers also examined Rovo’s ResearchAgent, which can perform multi-source research and multi-step web navigation.
These autonomous capabilities potentially magnified RovoBlast’s impact.
Once malicious instructions entered a trusted session, an agent could retrieve sensitive data and potentially expose it externally with minimal user interaction.
According to Varonis, the tested attack generally required only the initial P2P interaction rather than more complex techniques used to circumvent AI guardrails.
The finding demonstrates why organizations should evaluate AI agents based not only on what information they can retrieve but also on what actions they can perform with that information.
How organizations can reduce enterprise AI exposure
Atlassian has addressed the disclosed RovoBlast vulnerability, but organizations using connected AI assistants should apply broader controls to reduce the impact of similar attacks.
Security teams should:
- Limit AI access to sensitive systems and remove unused connectors, integrations, and data sources to reduce the potential blast radius.
- Apply least-privilege permissions and use dedicated AI service identities where possible to restrict access and improve accountability.
- Treat external prompts and parameters as untrusted input and validate them before allowing sensitive actions or data access.
- Restrict autonomous capabilities and outbound access to prevent AI agents from unnecessarily browsing, executing multi-step actions, or transmitting data externally.
- Use data loss prevention controls to detect and block unauthorized exposure of confidential, regulated, or sensitive information.
- Monitor and log AI activity for unusual searches, unexpected data access, suspicious agent behavior, and interactions with external destinations.
- Test incident response plans with attack simulation tools and scenarios around prompt injection and other AI-powered attacks.
Together, these steps can reduce the attack surface of connected AI assistants and limit the potential impact when untrusted inputs reach trusted enterprise workflows.
Bottom line
RovoBlast underscores the security risks that emerge as AI assistants gain deeper access to enterprise systems, data, and workflows.
While greater connectivity can improve productivity, each additional permission, integration, and autonomous capability expands the potential blast radius if an attacker successfully manipulates the AI.
Securing enterprise AI requires controls that extend beyond prompt filtering.
Organizations must enforce clear trust boundaries around what AI assistants can access, what actions agents can perform, and how external or untrusted inputs are handled before they reach sensitive resources.





