PT-2026-96951 · Unknown · Mcp-Attlasian
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions 0.17.0 through 0.21.0
Description
A path traversal issue exists in the
confluence upload attachment tool. The file path variable is passed directly to the open() function without proper validation, allowing a caller to read arbitrary files accessible by the server process. These files can then be exfiltrated by uploading them to an attacker-controlled Confluence host. In default streamable-http transport deployments, the server binds to 0.0.0.0 without authentication, which may allow remote exploitation. This issue is a read-side counterpart to a previous arbitrary file write flaw.Recommendations
Update to version 0.22.0.
As a temporary mitigation, restrict the use of the
confluence upload attachment tool or ensure the server is not exposed to untrusted networks.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Attlasian