PT-2026-96954 · Unknown · Mcp-Attlasian

·

CVE-2026-77269

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description The confluence upload attachment and confluence upload attachments tools do not validate that the provided source path is confined to an allowed directory before opening the file. A caller can provide an absolute or traversal file path to the upload attachment() function, allowing the server to read and upload any local file accessible to the process, such as SSH keys, .env files, or API credentials, to Confluence. This issue stems from an incomplete fix where path validation was applied to download operations but omitted from upload operations.
Recommendations Update to version 0.22.0. As a temporary workaround, restrict the use of the file path parameter in the confluence upload attachment and confluence upload attachments tools to prevent the upload of sensitive local files.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77269
GHSA-H7WJ-5V37-59R2

Affected Products

Mcp-Attlasian