PT-2026-105843 · Pypi · Mcp-Attlasian

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Summary

The upload attachment method in confluence/attachments.py reads and uploads arbitrary local files to Confluence without calling validate safe path(). Both download methods (download attachment at line 223, download content attachments at line 272) correctly call validate safe path() before writing files, but the upload path at lines 35-79 skips this check entirely.
An AI agent connected via MCP (or an attacker influencing that agent through prompt injection) can read any file on the host and exfiltrate it by uploading it as a Confluence page attachment.

Vulnerable Code

File: src/mcp atlassian/confluence/attachments.py, lines 62-79
python
# No validate safe path() call anywhere in this method
if not os.path.isabs(file path):
  file path = os.path.abspath(file path)

if not os.path.exists(file path):
  return {"success": False, "error": f"File not found: {file path}"}

filename = os.path.basename(file path)
attachment = self. upload attachment direct(
  content id, file path, filename, comment, minor edit
)
The validate safe path function is already imported at line 9 of the same file, and used in the download methods. It was just not added to the upload path.

Proof of Concept

Tested with mcp-atlassian 0.21.1 on Python 3.11 (EC2, Amazon Linux 2023).
python
import inspect
from mcp atlassian.confluence.attachments import AttachmentsMixin

# Confirm: no validate safe path in upload
source = inspect.getsource(AttachmentsMixin.upload attachment)
assert "validate safe path" not in source # passes

# Confirm: validate safe path IS in downloads
assert "validate safe path" in inspect.getsource(AttachmentsMixin.download attachment) # passes
assert "validate safe path" in inspect.getsource(AttachmentsMixin.download content attachments) # passes
An MCP tool call like this reads /etc/passwd and uploads it to Confluence:
json
{"tool": "confluence upload attachment", "arguments": {"content id": "123456", "file path": "/etc/passwd"}}

Impact

Exfiltration of any file readable by the MCP server process: SSH keys, AWS credentials, .env files, /etc/passwd, application secrets. Data leaves the local machine and lands on a remote Confluence instance accessible to other users.

Suggested Fix

Add validate safe path(file path) before the os.path.exists() check in upload attachment, matching the existing pattern in the download methods. The function is already imported.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-4088

Affected Products

Mcp-Attlasian