{
  "id": 332530,
  "title": "RovoBlast: One-Click Hijacking of Enterprise AI Permissions for Data Exfiltration",
  "url": "https://urgent.news/2026/08/09/rovoblast-one-click-hijacking-of-enterprise-ai-permissions-for-data",
  "topic": "culture",
  "section": "Culture",
  "published": "2026-08-09T01:52:15.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/rovoblast-one-click-hijacking-of-enterprise-ai-permissions-for-data-exfiltration-48ob"
  },
  "original_language": "en",
  "account": "Atlassian's Rovo AI platform has been found to have a critical one-click vulnerability that allows attackers to hijack enterprise AI permissions and exfiltrate data. By tricking a user into clicking a specially crafted URL, the attacker can cause Rovo to treat external input as a trusted user prompt. This enables the Rovo Chat to search sensitive data sources like Jira, Confluence, SharePoint, and other connected systems using the user's permissions. The stolen information is then externally sent via the ResearchAgent's autonomous web operations. The vulnerability, dubbed RovoBlast, has been patched by Atlassian before public disclosure, but no active exploitation has been reported. The attack chain begins with the creation of a malicious link in the format https://home.atlassian.com/chat?rovoChatPathway=chat&rovoChatPrompt=attack_command. When an authenticated user clicks this link, Rovo Chat injects the external parameter into the session without any warnings. ResearchAgent then fetches information from internal data sources, transforms and summarizes it, and sends the data to an arbitrary website. Successful PoC attacks have exfiltrated Confluence pages, Jira tickets, and SharePoint content containing personal data.",
  "summary": "RovoBlast: One-Click Hijacking of Enterprise AI Permissions for Data Exfiltration 1. Basic Information Article Title : Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data Publisher : SecurityWeek Publication Date : August 8, 2026, 07:30 ET (20:30 JST) Original Source : SecurityWeek Primary Source : Varonis Threat Labs Attack Name : RovoBlast Attack Techniques :…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}