PT-2026-96928 · Unknown · Mcp-Attlasian
CVE-2026-77260
·
Published
2026-09-22
·
Updated
2026-09-29
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
An arbitrary local file read issue exists in the Confluence and Jira
upload attachment tool paths. The implementation accepts an unconstrained file path and opens the referenced server-local file without restricting it to a safe base directory. This allows a permitted caller to exfiltrate sensitive host files, such as /etc/passwd or cloud credential files, by uploading them as attachments to an Atlassian destination. The Jira update issue tool also exposes this behavior via its attachments parameter. This can be exploited through prompt injection in LLM agent deployments or via direct calls to the HTTP transport if bound to a non-loopback address.Recommendations
Update to version 0.22.0.
As a temporary mitigation, restrict the use of the
upload attachment tool and the attachments parameter in the update issue tool until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Attlasian