PT-2026-96945 · Unknown+1 · Mcp-Attlasian+2
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
Jira and Confluence attachment upload tools accept arbitrary local filesystem paths and send the selected bytes to Atlassian. In HTTP or multi-user deployments, a caller can cross the client-to-server filesystem boundary to disclose configuration, credentials, mounted secrets, or other files readable by the MCP process. This server-side arbitrary file read and exfiltration occurs because the implementation converts relative paths to absolute paths and opens them without validating if the path is safe or restricted to an allowed directory.
The issue affects the following components:
- API Endpoints: The attachment upload tools for Jira and Confluence.
- Vulnerable Parameters: The
file pathparameter and theattachmentsfield (which accepts JSON or CSV local paths). - Function Names:
jira upload attachment(),confluence upload attachment(), andupload attachment().
Recommendations
Update MCP Atlassian to version 0.22.0.
As a temporary mitigation, set
READ ONLY MODE=true to block the affected write tools.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Confluence
Jira
Mcp-Attlasian