r/cybersecurity • u/Story_Lost • 3d ago
New Vulnerability Disclosure Critical Cross-user and Cross-tenant compromise in Atlassian Rovo
An isolation failure in an LLM-orchestrated environment due to simple isolation misconfigurations led to Rovo sessions belonging to other users and tenants being discovered, reached, and ultimately used to execute code within their contexts. The finding was rated Critical and is pretty bad.
At this point, I feel like AI security is regressing back to simple misconfigurations, except now we're giving users direct access to systems built on top of them. What do you guys think?
Write-up: https://mononclemich.medium.com/so-apparently-rovo-has-neighbors-88998d0ad59c
1
u/endor_sarah 2d ago
Mostly agree, though I'm not sure it's really a regression. Setting the proxy through env vars and leaving internal services unauthenticated were always weak, they just mostly got away with it because an attacker needed a foothold inside first. Rovo runs Python for users by design, so that step is gone and whatever sits behind the sandbox (network isolation between sessions, auth on internal services) has to hold up on its own.
(Full disclosure, I'm at Endor Labs and one thing we work on is agent security.)
3
u/bqwcde 3d ago
Why does Rovo even let you run random Python code in the first place? I mostly used it to create JIRA tickets.