PT-2026-96949 · Unknown · Mcp-Attlasian

CVE-2026-77257

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description HTTP-exposed Jira and Confluence upload tools allow a remote caller to provide a file path that is passed to local file operations without being restricted to a specific workspace. This allows an authenticated caller or a prompt-injected agent with tool-call capability to read sensitive local files—such as API tokens, OAuth credentials, and service configurations—and upload them as attachments to Jira issues or Confluence pages. The issue occurs because the server fails to validate that the upload source path resolves within a restricted base directory, implicitly trusting that any file the MCP process can read is authorized for upload.
Technical details include the following affected components:
  • API Endpoints: streamable-http and SSE endpoints.
  • Vulnerable Parameters: file path and attachments.
  • Function Names: upload attachment() and processTransaction() (via the upload attachments flow).
Recommendations Update MCP Atlassian to version 0.22.0. As a temporary mitigation, enable READ ONLY MODE=true to block write operations. Restrict access to the file path and attachments parameters in the affected upload tools until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77257
GHSA-MRQ8-FV7V-HHJG

Affected Products

Mcp-Attlasian