Impact
MCP Atlassian allows a client with write‑tool access to supply an arbitrary file_path when uploading attachments to Confluence or Jira. The path is not confined to a sanctioned workspace, enabling an attacker to read any file on the MCP server that the service process can access, including environment credentials or data belonging to other tenants. The vulnerability is a classic path traversal flaw (CWE‑22) compounded by relative‑path resolution issues (CWE‑73).
Affected Systems
The flaw exists in all releases of MCP Atlassian prior to version 0.22.0, as documented in the source code for the confluence_upload_attachment, confluence_upload_attachments, Updating to 0.22.0 or later removes the vulnerable code paths.
Risk and Exploitability
With a CVSS score of 7.7 the issue is considered high severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, but the remote nature and lack of required local privileges make exploitation likely in any multi‑user or SSE deployment where a client can invoke the vulnerable attachment upload functions. The vulnerability is not listed in the CISA KEV catalog, but its potential for cross‑tenant data leakage makes it a substantial risk for exposed or shared MCP instances.
OpenCVE Enrichment