PT-2026-105843 · Pypi · Mcp-Attlasian
Publicado
2026-10-01
·
Atualizado
2026-10-01
CVSS v3.1
7.7
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Summary
The
upload attachment method in confluence/attachments.py reads and uploads arbitrary local files to Confluence without calling validate safe path(). Both download methods (download attachment at line 223, download content attachments at line 272) correctly call validate safe path() before writing files, but the upload path at lines 35-79 skips this check entirely.An AI agent connected via MCP (or an attacker influencing that agent through prompt injection) can read any file on the host and exfiltrate it by uploading it as a Confluence page attachment.
Vulnerable Code
File:
src/mcp atlassian/confluence/attachments.py, lines 62-79python
# No validate safe path() call anywhere in this method
if not os.path.isabs(file path):
file path = os.path.abspath(file path)
if not os.path.exists(file path):
return {"success": False, "error": f"File not found: {file path}"}
filename = os.path.basename(file path)
attachment = self. upload attachment direct(
content id, file path, filename, comment, minor edit
)The
validate safe path function is already imported at line 9 of the same file, and used in the download methods. It was just not added to the upload path.Proof of Concept
Tested with mcp-atlassian 0.21.1 on Python 3.11 (EC2, Amazon Linux 2023).
python
import inspect
from mcp atlassian.confluence.attachments import AttachmentsMixin
# Confirm: no validate safe path in upload
source = inspect.getsource(AttachmentsMixin.upload attachment)
assert "validate safe path" not in source # passes
# Confirm: validate safe path IS in downloads
assert "validate safe path" in inspect.getsource(AttachmentsMixin.download attachment) # passes
assert "validate safe path" in inspect.getsource(AttachmentsMixin.download content attachments) # passesAn MCP tool call like this reads /etc/passwd and uploads it to Confluence:
json
{"tool": "confluence upload attachment", "arguments": {"content id": "123456", "file path": "/etc/passwd"}}Impact
Exfiltration of any file readable by the MCP server process: SSH keys, AWS credentials, .env files, /etc/passwd, application secrets. Data leaves the local machine and lands on a remote Confluence instance accessible to other users.
Suggested Fix
Add
validate safe path(file path) before the os.path.exists() check in upload attachment, matching the existing pattern in the download methods. The function is already imported.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mcp-Attlasian