PT-2026-96904 · Unknown · Mcp-Attlasian
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
A backslash authority confusion exists in the header-based Jira and Confluence URL authentication flow. The
validate url for ssrf() function interprets the authority of a URL differently than the Requests connection layer. By using a crafted URL containing a backslash before userinfo-like syntax, an attacker can bypass SSRF (Server-Side Request Forgery) protections. In this scenario, the validation function identifies an external hostname as the target, while the HTTP client connects to an internal host, allowing unauthorized server-side requests to protected network resources, such as loopback or internal services. This issue can be triggered via the POST /mcp endpoint by providing a malicious URL in the X-Atlassian-Jira-Url or X-Atlassian-Confluence-Url headers.Recommendations
Update MCP Atlassian to version 0.22.0.
As a temporary mitigation, restrict or validate the input provided to the
X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers to prevent the use of backslashes in the authority section of the URL.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Attlasian