PT-2026-96942 · Unknown+1 · Mcp-Attlasian+2
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
Jira and Confluence upload tools interpret caller-controlled path arguments on the MCP server and open those files before sending them as attachments. This allows a permitted client to disclose and exfiltrate host files from the server's local filesystem without requiring shell or direct filesystem access. The issue is particularly critical in remote or multi-user deployments (such as those using
sse or streamable-http), where the MCP server process may have access to sensitive data like application configurations, deployment secrets, or service account tokens.Technical details include the following vulnerable components:
- API Endpoints:
jira update issue - Vulnerable Parameters or Variables:
file pathandfile paths - Function Names:
upload attachment(),upload attachments(), andupload attachment direct()
Recommendations
Update MCP Atlassian to version 0.22.0.
As a temporary workaround, restrict access to the
upload attachment() and upload attachments() functions to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Confluence
Jira
Mcp-Attlasian