Atlassian Rovo, an enterprise AI assistant, is subject to two distinct Indirect Prompt Injection (XPIA) attack vectors that threaten cross-platform data integrity. While the "RovoBlast" one-click vulnerability via the rovoChatPrompt URL parameter was patched in July 2026, a more severe zero-click vector remains unconfirmed for remediation. This second vector utilizes malicious instructions embedded within file metadata or content to hijack Rovo’s internal URL retrieval and grounding tools. Once triggered, the attack enables silent, unauthorized exfiltration of sensitive information from interconnected platforms, including Jira, Confluence, Slack, Google Workspace, and Microsoft 365, effectively bypassing "web search disabled" security configurations.
- Threat Model & Vulnerability Overview
- Targets Atlassian Rovo’s deep integration with enterprise SaaS ecosystems.
- Utilizes Indirect Prompt Injection (XPIA) to manipulate LLM reasoning and execution.
- Exploits the assistant's capability to process and "ground" information from external files and URLs.
- Attack Mechanics: RovoBlast vs. Zero-Click
- RovoBlast (Mitigated): A one-click exploitation method utilizing manipulated
rovoChatPromptURL parameters. - Zero-Click Vector (Active/Unconfirmed): Injection of malicious instructions directly into file content or metadata.
- Execution Path: Rovo's internal URL retrieval/grounding tool processes the uploaded file, triggering the hidden instructions.
- RovoBlast (Mitigated): A one-click exploitation method utilizing manipulated
- Systemic & Security Impact
- Data Scope: Enables potential total access to all Jira tickets, Confluence pages, and connected third-party SaaS data.
- Exfiltration Capabilities: Targets high-value integrated platforms including SharePoint, Slack, Google Workspace, and M365.
- Security Bypass: Capable of circumventing organizational security policies that specifically disable web search functionality.
- Remediation & Defensive Outlook
- Patch Status: The RovoBlast one-click vector was officially remediated by Atlassian in July 2026.
- Persistent Risk: As of August 2026, the remediation status of the file-based zero-click injection remains unconfirmed.
- Defensive Action: Organizations should prioritize monitoring for anomalous API calls and unauthorized data transfers originating from Rovo connectors.
Related posts
- datawater.com — Atlassian Rovo XPIA: Uploaded File Silently Exfiltrates All Jira and Confluence Data — Disabling Web Search Doesn’t Stop It, 75 Days After Disclosure Still Unconfirmed Closed, RovoBlast Fixed but Second Route Open
- eSecurity Planet — DEF CON 34: RovoBlast Exposes Atlassian Rovo Data Risks
- varonis.com — RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data
- feeds.feedburner.com — Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
- Enterprisedna
- SecurityWeek — Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data