PT-2026-96903 · Unknown · Mcp-Attlasian
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
The Jira and Confluence attachment upload tools fail to validate file paths, allowing for path traversal. An authenticated MCP client or an AI assistant manipulated via prompt injection can provide arbitrary values to the
file path variable, which the server treats as trusted local paths. This allows the disclosure and exfiltration of any file readable by the server process, such as environment files, SSH keys, and application configurations, by uploading them to a Confluence page or Jira issue. The issue occurs within the confluence upload attachment and jira upload attachment functions, specifically where open(file path, "rb") is called without using the validate safe path utility.Recommendations
Update MCP Atlassian to version 0.22.0.
As a temporary workaround, restrict write access to the MCP server to prevent the use of upload tools until the update is applied.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Attlasian