Varonis Threat Labs uncovered a vulnerability in Rovo, Atlassian’s enterprise AI assistant. Dubbed RovoBlast, a single click on a link triggers the attacker’s embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user’s session. No jailbreaks, no permission bypass, and no warnings or confirmation.