Rovo One-Click Flaw Lets Prompt Injection Potentially Expose Enterprise Data
Atlassian’s enterprise AI assistant Rovo, connected to tools like Slack, Microsoft 365, and Google Workspace, was found vulnerable to prompt-injection data leaks. A single click on a crafted link can trigger embedded instructions that make Rovo trust externally supplied parameters, potentially allowing access to anything it can access. Rovo connects to 50+ platforms and can’t be fully uninstalled, with built-in automation that could accelerate exfiltration. Atlassian did not immediately comment.