PT-2026-96926 · Unknown · Mcp-Attlasian
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
Three distinct issues allow attacker-controlled queries to access content from forbidden projects or spaces, bypassing the restrictions set by the
JIRA PROJECTS FILTER and CONFLUENCE SPACES FILTER environment variables. These filters are intended to limit MCP clients, such as prompt-injected LLM agents, to a specific subset of the workspace.The issues occur in the following areas:
- In the
jira searchfunction, a substring check is bypassed when a user provides a JQL query containingproject = <forbidden-project>, allowing access to projects not in the allowlist. - In the
confluence searchfunction, the substring check forspace =is case-sensitive, meaning a query usingSPACE = <forbidden-space>bypasses the filter. - The
get board issues()andget agile boards()functions completely omit theprojects filterenforcement, allowing the enumeration of boards and issues across the entire workspace.
These flaws are exploitable when the operator's credentials have broader access permissions than the intended allowlist.
Recommendations
Update MCP Atlassian to version 0.22.0.
As a temporary mitigation, restrict the permissions of the Personal Access Token (PAT) used by the operator to only the projects and spaces that should be accessible.
Exploit
Fix
Incorrect Authorization
Incomplete List of Disallowed Inputs
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp-Attlasian