PT-2026-96925 · Unknown · Mcp-Attlasian

·

CVE-2026-77250

·

Published

2026-09-22

·

Updated

2026-09-29

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description OAuthConfig writes a plaintext fallback file containing access token and refresh token within the user's .mcp-atlassian directory. This file is created using process-default permissions rather than restrictive ones. On systems with a permissive umask, local users or processes in the same group can read these persisted tokens and reuse them to gain unauthorized access to Atlassian products. The issue occurs during the execution of the OAuthConfig. save tokens() function, which unconditionally maintains a plaintext copy of the tokens in ~/.mcp-atlassian/oauth-<client id>.json for backwards compatibility, even when keyring storage is successful.
Recommendations Update MCP Atlassian to version 0.22.0.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77250
GHSA-G5XV-MHGM-V5F6

Affected Products

Mcp-Attlasian