Atlassian Rovo AI data leak via malicious links
Atlassian Rovo's AI assistant can leak your company's private data if you click an attacker's link. Attackers trick the AI into fetching and sending sensitive info from your work apps.
- Report priority
- Medium
- Targets
- Atlassian+5 more
How it works
- An attacker sends a specially made link that tricks Atlassian Rovo's AI into running commands it shouldn't.
- The AI then fetches and sends private company data from connected apps without you noticing.
What to do
Check if you use Atlassian Rovo and have linked it to your company's apps or data sources. If so, you're affected unless you've updated to the fixed version.
Update Rovo to the latest version through Atlassian's official update channel and verify the installed version in your Rovo settings.
Technical details
Affected software: Atlassian, Apache, Linux, Android, OpenSSL, Anthropic
You get a link in a work chat or email. When you click it, the AI inside Rovo thinks it's a normal request but secretly pulls data from your company's apps, like customer lists or project files, and sends it to the attacker. The hacker now has your company's private info without breaking in.
Atlassian Rovo, an enterprise AI assistant integrated with Jira, Confluence, Bitbucket, and third-party services, suffers from RovoBlast (NEWS-2c7f683b001f431c1c), a flaw where a malicious link forces attacker-controlled instructions into a user's authenticated session. Researchers Dolev Taler and Mark Vaitsman (Varonis Threat Labs) demonstrated that by crafting a link targeting Rovo's rovoChatPrompt parameter, an attacker could inject arbitrary prompts into the AI assistant. Since Rovo operates with elevated permissions, searching, querying, and acting across connected systems, this allowed sensitive data retrieval without requiring traditional permission bypasses or jailbreaks.
The attack leverages a Parameter-to-Prompt (P2P) technique, previously documented in Microsoft Copilot vulnerabilities, exploiting untrusted input in AI-driven workflows. Atlassian addressed the issue after responsible disclosure.
References
- docs.gitlab.com · patch-release-gitlab-18-11-9-released (patches) patch release notes
- varonis.com · rovoblast eSecurityPlanet
- varonis.com · reprompt eSecurityPlanet
- thehackernews.com · ai-assisted-http-terminator-finds-novel.html TheHackerNews
- wid.cert-bund.de · securityadvisory CERT-Bund Advisories
- acn.gov.it · aggiornamenti-di-sicurezza-per-prodotti-veeam-1 ACN CSIRT Italy
- acn.gov.it · risolte-vulnerabilita-in-openssl-2 ACN CSIRT Italy
- cisecurity.org · multiple-vulnerabilities-in-solarwinds-web-help-desk-could-allow-for-authentication-bypass_2026-077 MS-ISAC
- infosecurity-magazine.com · anthropic-claude-breached-three Infosecurity Magazine
- neuracybintel.com · levi-strauss-confirms-social-engineering-attack-that-allowed-hackers-to-steal-corporate-data-from-employee-computers NeuraCybIntel
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0962 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0968 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0973 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0975 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0976 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0977 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0988 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0993 CERT-FR Advisories
- acn.gov.it · adobe-aggiornamenti-di-sicurezza-20 ACN CSIRT Italy
- sygnia.co · when-ransomware-hides-in-onedrive-inside-safepay-exfiltration-play Sygnia
- darkreading.com · metabase-sql-zero-day-attacks-wide-blast-radius DarkReading
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0969 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0981 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0982 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0992 CERT-FR Advisories
- securityonline.info · greatness-phaas-aitm-phishing SecurityOnline
- thehackernews.com · kimsuky-builds-offline-ai-stack-that.html TheHackerNews
- gbhackers.com · cncmachinerms-rat GBHackers
- thehackernews.com · bdthemes-supply-chain-attack-poisons.html TheHackerNews
- thehackernews.com · metabase-zero-day-exploited-in-wild.html TheHackerNews
- thehackernews.com · teampcp-linked-to-redis-attacks-dating.html TheHackerNews
- gitlab.com · 10036 GitLab Security Releases
- gitlab.com · 3006 GitLab Security Releases
- gitlab.com · 244020 GitLab Security Releases
- gitlab.com · 244214 GitLab Security Releases
- gitlab.com · 244097 GitLab Security Releases
- gitlab.com · 245799 GitLab Security Releases
- gitlab.com · 247963 GitLab Security Releases
- gitlab.com · 9560 GitLab Security Releases
- cert.ssi.gouv.fr · CERTFR-2026-AVI-0979 CERT-FR Advisories