PT-2026-96901 · Unknown · Mcp-Attlasian
CVE-2026-77258
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
The
upload attachment function in src/mcp atlassian/confluence/attachments.py fails to call validate safe path(), allowing it to accept a caller-controlled file path and open server-local files without restricting them to the workspace. An AI agent or an attacker using prompt injection can read any file accessible to the server process—such as SSH keys, AWS credentials, and application secrets—and exfiltrate this data by uploading the files as attachments to a Confluence page.Recommendations
Update MCP Atlassian to version 0.22.0.
As a temporary workaround, restrict the permissions of the server process to ensure it cannot access sensitive system files.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Attlasian