PT-2026-96944 · Unknown · Mcp-Attlasian

·

CVE-2026-77249

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description A server-side request forgery (SSRF) exists due to an incomplete fix for a previous issue. The JiraUserMixin. lookup user by permissions function uses the module-level requests.get function instead of the protected session. This allows an unauthenticated attacker using HTTP multi-tenant transport mode to provide a public Jira URL that passes initial validation but subsequently redirects the request to an internal address. Because the module-level call bypasses the redirect-validation hook make ssrf safe hook, the server follows the redirect to an arbitrary internal host and port. This results in a blind SSRF, enabling internal service reachability, port discovery, and access to cloud metadata endpoints.
Recommendations Update to version 0.22.0. As a temporary mitigation, restrict access to the HTTP transport endpoint to minimize the risk of unauthenticated exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77249
GHSA-V9M3-WFH8-5646

Affected Products

Mcp-Attlasian