PT-2026-96929 · Unknown · Mcp-Attlasian

CVE-2026-77261

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description A Server-Side Request Forgery (SSRF) issue exists where the make ssrf safe hook() function, designed to block HTTP redirects to private or internal IP addresses by validating the Location header, is not applied to sessions created via basic-auth and oauth pat authentication branches. Consequently, if a compromised or attacker-controlled Atlassian instance returns a redirect to an internal address, the JiraFetcher and ConfluenceFetcher sessions may follow the redirect without revalidating the destination. This could allow an attacker to access internal infrastructure reachable from the MCP server's network, such as cloud metadata endpoints or internal APIs.
Recommendations Update to version 0.22.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77261
GHSA-6529-C226-H328

Affected Products

Mcp-Attlasian