PT-2026-96943 · Unknown · Mcp-Attlasian
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
In multi-user HTTP deployments using the
--transport streamable-http configuration, the server exposes all tools to unauthenticated network clients. This occurs because the UserTokenMiddleware. parse auth header function allows requests without an Authorization header to pass through, causing the get fetcher function to fall back to the global operator credentials. Additionally, the upload attachment tool accepts a file path variable without path validation, allowing it to be passed unsanitized into an open() call. An unauthenticated attacker can exploit this by providing a sensitive local file path (such as /etc/passwd or .env files) via the file path variable, uploading the file to an attacker-selected Jira issue or Confluence page, and subsequently retrieving the contents. This allows for arbitrary local file read on the MCP server host and unauthorized use of Atlassian tools with operator privileges.Recommendations
Update MCP Atlassian to version 0.22.0.
As a temporary workaround, restrict network access to the streamable-http transport or avoid using the
upload attachment tool until the update is applied.Exploit
Fix
Path traversal
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp-Attlasian