PT-2026-96955 · Atlassian · Mcp-Attlasian

·

CVE-2026-77272

·

Published

2026-09-22

·

Updated

2026-09-28

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description The OAuth 2.0 setup wizard's local callback HTTP server reflects the error query parameter directly into an HTML response without sanitization or encoding. This occurs within the CallbackHandler class in oauth setup.py, where the error parameter is passed to the send response() function and interpolated into an HTML page. A crafted authorization callback can inject markup or scripts that execute in the browser of a user completing the OAuth flow. The risk is increased because the server binds to all network interfaces (0.0.0.0), making it accessible from the local network, and lacks security headers such as Content-Security-Policy and X-Content-Type-Options.
Recommendations Update to version 0.22.0. As a temporary mitigation, restrict network access to the callback port (default 8080) to prevent external access during the OAuth setup process.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77272
GHSA-G2R2-3J32-J27X

Affected Products

Mcp-Attlasian