Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Diemoeve

#44302of 57,305
6.5Total CVSS
Vulnerabilities · 1
PT-2026-96954
6.5
2026-09-22
Unknown · Mcp-Attlasian · CVE-2026-77269
**Name of the Vulnerable Software and Affected Versions** MCP Atlassian versions prior to 0.22.0 **Description** The `confluence upload attachment` and `confluence upload attachments` tools do not validate that the provided source path is confined to an allowed directory before opening the file. A caller can provide an absolute or traversal `file path` to the `upload attachment()` function, allowing the server to read and upload any local file accessible to the process, such as SSH keys, `.env` files, or API credentials, to Confluence. This issue stems from an incomplete fix where path validation was applied to download operations but omitted from upload operations. **Recommendations** Update to version 0.22.0. As a temporary workaround, restrict the use of the `file path` parameter in the `confluence upload attachment` and `confluence upload attachments` tools to prevent the upload of sensitive local files.