| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mrq8-fv7v-hhjg | MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 23 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sooperset
Sooperset mcp-atlassian |
|
| Vendors & Products |
Sooperset
Sooperset mcp-atlassian |
Tue, 22 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, HTTP-exposed Jira and Confluence upload tools pass a caller-provided file_path to local file operations without restricting it to the workspace. A remote MCP caller with tool access can cause the server to read sensitive local files and upload them as Atlassian attachments. The advisory traces the vulnerable input and processing flow through streamable-http, upload_attachment, and file_path, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0. | |
| Title | MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T14:37:52.861Z
Reserved: 2026-08-20T19:02:23.417Z
Link: CVE-2026-77257
Updated: 2026-09-22T19:11:16.230Z
Status : Awaiting Analysis
Published: 2026-09-22T19:16:50.163
Modified: 2026-09-23T18:12:04.247
Link: CVE-2026-77257
No data.
OpenCVE Enrichment
Updated: 2026-09-22T20:00:11Z
Github GHSA