PT-2026-96931 · Unknown · Mcp-Attlasian
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions 0.17.0 through 0.21.0
Description
An incomplete path traversal fix allows attacker-selected writes within the working directory. The function
validate safe path() defaults its base dir to the current working directory (os.getcwd()) when no explicit directory is provided. In standard container deployments, this allows paths within the application directory to pass validation. Specifically, call sites in src/mcp atlassian/confluence/attachments.py omit the base dir, enabling an attacker to overwrite Python source modules. This can lead to remote code execution when the application imports the modified module, typically following a process restart.Recommendations
Update MCP Atlassian to version 0.22.0.
As a temporary mitigation, restrict access to the MCP HTTP port to prevent unauthorized tool calls.
Exploit
Fix
Code Injection
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp-Attlasian