PT-2026-96950 · Unknown · Mcp-Attlasian

·

CVE-2026-77259

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description Missing path validation in the confluence upload attachment function allows an authenticated client to read arbitrary files from the server filesystem and exfiltrate their contents to a Confluence page. The issue occurs because the upload attachment() function in src/mcp atlassian/confluence/attachments.py opens the caller-supplied file path variable without performing a boundary check to ensure the resolved path remains within the intended workspace. On Linux deployments, this can be used to access /proc/self/environ, exposing runtime secrets and API tokens. The vulnerable processing flow involves the confluence upload attachment tool, the file path variable, and the open() function.
Recommendations Update MCP Atlassian to version 0.22.0. As a temporary workaround, restrict the use of the confluence upload attachment function to prevent unauthorized file uploads.

Exploit

Fix

Files Accessible to External Parties

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77259
GHSA-6CR4-CCF3-X7H4

Affected Products

Mcp-Attlasian