Varonis Threat Labs disclosed a Parameter-to-Prompt (P2P) vulnerability in Atlassian Rovo where a crafted URL using the rovoChatPrompt parameter injects attacker instructions directly into a user's trusted Rovo Chat session. Rovo's federated access across Atlassian products and connected SaaS platforms, combined with the ResearchAgent tool's ability to browse and post to arbitrary external websites, created a one-click data exfiltration chain requiring no jailbreak or guardrail bypass. Atlassian fixed the vulnerability after responsible disclosure via Bugcrowd.
AI Data Exfiltration
1 post
RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data