๐Ÿ” CVE Alert

CVE-2026-77270

MEDIUM 6.5

MCP Atlassian: Arbitrary File Read via Upload Attachment Tools

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths. The server opens the selected file and uploads it to an Atlassian issue or page, allowing an MCP caller with upload access to disclose any file readable by the server process. The advisory traces the vulnerable input and processing flow through confluence_upload_attachment, jira_upload_attachment, file_path, and open(file_path, "rb"), which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

CWE CWE-22
Vendor sooperset
Product mcp-atlassian
Published Sep 22, 2026
Last Updated Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for sooperset mcp-atlassian

Be the first to know when new medium vulnerabilities affecting sooperset mcp-atlassian are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

sooperset / mcp-atlassian
< 0.22.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-f26r-j276-ggg4 github.com: https://github.com/sooperset/mcp-atlassian/pull/1448 github.com: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460 github.com: https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0