PT-2026-96945 · Unknown+1 · Mcp-Attlasian+2

·

CVE-2026-77253

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description Jira and Confluence attachment upload tools accept arbitrary local filesystem paths and send the selected bytes to Atlassian. In HTTP or multi-user deployments, a caller can cross the client-to-server filesystem boundary to disclose configuration, credentials, mounted secrets, or other files readable by the MCP process. This server-side arbitrary file read and exfiltration occurs because the implementation converts relative paths to absolute paths and opens them without validating if the path is safe or restricted to an allowed directory.
The issue affects the following components:
  • API Endpoints: The attachment upload tools for Jira and Confluence.
  • Vulnerable Parameters: The file path parameter and the attachments field (which accepts JSON or CSV local paths).
  • Function Names: jira upload attachment(), confluence upload attachment(), and upload attachment().
Recommendations Update MCP Atlassian to version 0.22.0. As a temporary mitigation, set READ ONLY MODE=true to block the affected write tools.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77253
GHSA-VC25-24VV-FXXM

Affected Products

Confluence
Jira
Mcp-Attlasian