PT-2026-97002 · Unknown · Mcp-Attlasian
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MCP Atlassian versions prior to 0.22.0
Description
An unauthenticated server-side file exfiltration issue exists when the server is deployed using HTTP transport (such as
streamable-http or sse) and READ ONLY MODE is set to false. A remote attacker can bypass authentication by providing specific service headers, such as X-Atlassian-Confluence-Url and X-Atlassian-Confluence-Personal-Token, to redirect requests to an attacker-controlled hostname. By invoking the confluence upload attachment function or its Jira equivalent in src/mcp atlassian/jira/attachments.py with a server-local file path variable, the attacker can force the MCP process to read and send any file accessible by the server process to the external endpoint. This occurs because the upload functionality lacks path validation, failing to use the validate safe path() function to restrict directory access.Recommendations
Update to version 0.22.0.
As a temporary mitigation, set
READ ONLY MODE=true for remotely reachable deployments.
Restrict the MCP ALLOWED URL DOMAINS allowlist to only include trusted hostnames.Exploit
Fix
Information Disclosure
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp-Attlasian