PT-2026-96949 · Unknown · Mcp-Attlasian
CVE-2026-77257
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
HTTP-exposed Jira and Confluence upload tools allow a remote caller to provide a
file path that is passed to local file operations without being restricted to a specific workspace. This allows an authenticated caller or a prompt-injected agent with tool-call capability to read sensitive local files—such as API tokens, OAuth credentials, and service configurations—and upload them as attachments to Jira issues or Confluence pages. The issue occurs because the server fails to validate that the upload source path resolves within a restricted base directory, implicitly trusting that any file the MCP process can read is authorized for upload.Technical details include the following affected components:
- API Endpoints:
streamable-httpand SSE endpoints. - Vulnerable Parameters:
file pathandattachments. - Function Names:
upload attachment()andprocessTransaction()(via theupload attachmentsflow).
Recommendations
Update MCP Atlassian to version 0.22.0.
As a temporary mitigation, enable
READ ONLY MODE=true to block write operations.
Restrict access to the file path and attachments parameters in the affected upload tools until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Attlasian