PT-2026-96952 · Unknown · Mcp-Attlasian
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
The
upload attachment() function in both the Jira and Confluence modules fails to constrain the resolved path to the server workspace, allowing the use of absolute paths and traversal sequences. This occurs because the function does not call validate safe path(), enabling an authenticated MCP caller with attachment access to read arbitrary server-local files (such as /etc/passwd or /proc/self/environ) and exfiltrate them by uploading them as attachments to a Jira or Confluence instance. The issue affects the upload attachment() function in src/mcp atlassian/jira/attachments.py and src/mcp atlassian/confluence/attachments.py, as well as the upload attachment direct() function in src/mcp atlassian/confluence/attachments.py. The vulnerable parameter is file path.Recommendations
Update to version 0.22.0.
As a temporary workaround, restrict access to the
upload attachment() function in both the Jira and Confluence modules to minimize the risk of file exfiltration.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Attlasian