PT-2026-96929 · Unknown · Mcp-Attlasian
CVE-2026-77261
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
A Server-Side Request Forgery (SSRF) issue exists where the
make ssrf safe hook() function, designed to block HTTP redirects to private or internal IP addresses by validating the Location header, is not applied to sessions created via basic-auth and oauth pat authentication branches. Consequently, if a compromised or attacker-controlled Atlassian instance returns a redirect to an internal address, the JiraFetcher and ConfluenceFetcher sessions may follow the redirect without revalidating the destination. This could allow an attacker to access internal infrastructure reachable from the MCP server's network, such as cloud metadata endpoints or internal APIs.Recommendations
Update to version 0.22.0.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Attlasian