RovoBlast Link Seeds AI to Leak Internal Data

Security Week Feed · High sophistication
Last updated August 10, 2026

Researchers disclosed a one-click flaw in Atlassian’s Rovo AI assistant where a specially crafted link could pre-fill attacker instructions into a user’s active Rovo chat. After a user clicks once, Rovo’s autonomous agent features could pull sensitive data from connected systems (like Confluence, Jira, or SharePoint) and send it out to the open web. Atlassian fixed the issue before publication, and researchers recommend tightening integrations and monitoring AI assistant activity logs.

What Happened

Researchers disclosed a one-click flaw in Atlassian's Rovo AI assistant. A specially crafted link could seed attacker-controlled instructions into a user's live Rovo chat session using a URL parameter called rovoChatPrompt, which pre-fills content directly into the chat window. Notably, a single seeded link was generally enough to trigger the leak, and the organization ID portion of the URL could be left blank while still routing into the victim's default organization without any warning or indicator.

How the Data Leak Chain Worked

Once a user clicked the link, Rovo's built-in ResearchAgent tool could take over. This agent can autonomously conduct multi-source web research and navigate across arbitrary sites. That same capability allowed the seeded prompt to pull internal data from connected systems and push it out to the open web in a single automated chain. Researchers demonstrated this in three separate proof-of-concept scenarios, exfiltrating Confluence pages, Jira tickets, and SharePoint content containing personal data.

Why This Technique Succeeded

The attack blended a familiar social engineering hook, an unexpected link shared as if from a colleague, with a newer trust gap around AI assistants. Employees are used to scrutinizing links for phishing, but a link that opens a legitimate internal AI tool with a prompt already filled in looks different from a typical phishing lure. The lack of a clear organization indicator in the URL removed a visual cue that might have prompted suspicion, and the autonomous, multi-step nature of ResearchAgent meant the data gathering and exfiltration happened without further user interaction.

Red Flags to Watch For

  • An unexpected link that opens an AI assistant with text already filled in
  • A request asking the AI to summarize or collect internal content across multiple tools like Jira, Confluence, or SharePoint
  • No clear business reason for gathering broad internal data
  • Instructions implying results will be sent or posted to an external site

Building Resistance

Atlassian fixed the underlying issue before publication, but the incident points to broader lessons for any organization using AI assistants connected to internal systems. Recommended practices include treating AI-assistant links and pre-filled prompts like phishing attempts, verifying that any content provided to connected apps comes from a trusted source, limiting which systems the assistant can reach, disconnecting unused integrations, walling off sensitive areas such as legal, HR, and finance, disabling browsing or automation features that aren't actively needed, and pairing these controls with routine monitoring of assistant activity logs.

Key findings

  • A “specially crafted link” could seed attacker instructions into a user’s live Rovo session via a URL parameter (rovoChatPrompt).
  • The org ID portion of the URL could be left blank and still route into the victim’s default organization “without any warning or indicator.”
  • Rovo’s built-in ResearchAgent could autonomously retrieve internal data from connected sources and “push it out to the open web in a single automated chain.”
  • Varonis demonstrated proof-of-concept leakage of Confluence pages, Jira tickets, and SharePoint content containing personal data.
  • Atlassian fixed the issue before the research was published; mitigations include limiting reachable systems, disconnecting unused integrations, restricting sensitive areas (legal/HR/finance), disabling browsing/automation features not needed, and monitoring activity logs.

Who’s being targeted

  • Commonly targeted roles: All employees using Atlassian Rovo, Knowledge management / Confluence users, Engineering and Jira users, IT and Security teams managing SaaS integrations, HR, Legal, and Finance (high-sensitivity data owners).
  • Affected industries: Any enterprise using Atlassian Jira/Confluence/Bitbucket with Rovo, Organizations with Slack, Microsoft 365, Google Workspace, and SharePoint integrations.
  • Attack channels: email, website.
  • Impersonated: Internal colleague / project team member sharing an Atlassian Rovo link, Atlassian workflow helper / ‘ResearchAgent’ usage suggestion from a coworker.

Red flags to watch for

  • Unexpected link that opens an AI assistant with text already filled in
  • The AI request asks to summarize or collect internal content across tools (Jira/Confluence/SharePoint)
  • No clear reason why the sender needs broad internal data gathered
  • Agent is instructed to access multiple internal repositories (Confluence + Jira + SharePoint) without a clear business need
  • Instructions imply sending or posting results “to the open web” or to an external site
  • The link’s organization context is unclear (or looks incomplete)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Rovo AI vulnerability work?

A specially crafted link used a URL parameter called rovoChatPrompt to pre-fill attacker-controlled instructions directly into a user's live Rovo chat session, requiring only one click to trigger.

What data could be exposed by this flaw?

Researchers demonstrated proof-of-concept leakage of Confluence pages, Jira tickets, and SharePoint content containing personal data through Rovo's ResearchAgent tool.

Has the Rovo AI issue been fixed?

Yes, Atlassian fixed the issue before the research was published.

How can organizations reduce risk from AI assistant links like this?

Recommended mitigations include limiting which systems the AI assistant can reach, disconnecting unused integrations, restricting sensitive areas like HR and finance, disabling unused automation features, and monitoring assistant activity logs.

Read the video transcript

You get a chat: “Please review this Rovo chat link I made, it already has the prompt filled in.” Seems helpful, right? Behind that link, a rovoChatPrompt URL parameter silently seeds attacker instructions into your live Rovo chat, no org ID needed. One click, and ResearchAgent can grab Jira, Confluence, and SharePoint data, then push it out to the open web in a single automated chain. Here’s the aha: if a link opens Rovo and the prompt is already asking to sweep multiple tools or send results to an external site, that link is the phish. The vulnerability’s fixed, but the trick lives on in any AI assistant that accepts pre-filled prompts. Your move: if a Rovo or any AI link opens with a surprise, pre-filled prompt that wants broad internal data, close it and message the sender in a separate channel to confirm it’s real before you do anything.

Categories

Similar attacks

Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Zero-Click Prompts Hijack AI Browsers via Email/X

Zero-Click Prompts Hijack AI Browsers via Email/X

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing…

August 6, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026