Unknown · Mcp-Attlasian · CVE-2026-77247
**Name of the Vulnerable Software and Affected Versions**
MCP Atlassian versions prior to 0.22.0
**Description**
Jira and Confluence upload tools interpret caller-controlled path arguments on the MCP server and open those files before sending them as attachments. This allows a permitted client to disclose and exfiltrate host files from the server's local filesystem without requiring shell or direct filesystem access. The issue is particularly critical in remote or multi-user deployments (such as those using `sse` or `streamable-http`), where the MCP server process may have access to sensitive data like application configurations, deployment secrets, or service account tokens.
Technical details include the following vulnerable components:
- **API Endpoints:** `jira update issue`
- **Vulnerable Parameters or Variables:** `file path` and `file paths`
- **Function Names:** `upload attachment()`, `upload attachments()`, and ` upload attachment direct()`
**Recommendations**
Update MCP Atlassian to version 0.22.0.
As a temporary workaround, restrict access to the `upload attachment()` and `upload attachments()` functions to minimize the risk of exploitation.