Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassian/confluence/attachments.py upload_attachment, and the jira_update_issue attachments parameter reaches src/mcp_atlassian/jira/attachments.py upload_attachment, without confining either path to an approved server workspace. In a remote HTTP, SSE, or multi-user deployment, absolute or traversing paths are resolved on the MCP server and uploaded to Atlassian, allowing a client with write-tool access to disclose server files, environment-held Atlassian credentials, or another tenant's data. A local single-user stdio deployment does not cross this trust boundary because the server runs in the caller's environment. This issue is fixed in version 0.22.0.
Published: 2026-09-14
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: arbitrary server‑side file disclosure through attachment upload
Action: Immediate Patch
AI Analysis

Impact

MCP Atlassian allows a client with write‑tool access to supply an arbitrary file_path when uploading attachments to Confluence or Jira. The path is not confined to a sanctioned workspace, enabling an attacker to read any file on the MCP server that the service process can access, including environment credentials or data belonging to other tenants. The vulnerability is a classic path traversal flaw (CWE‑22) compounded by relative‑path resolution issues (CWE‑73).

Affected Systems

The flaw exists in all releases of MCP Atlassian prior to version 0.22.0, as documented in the source code for the confluence_upload_attachment, confluence_upload_attachments, Updating to 0.22.0 or later removes the vulnerable code paths.

Risk and Exploitability

With a CVSS score of 7.7 the issue is considered high severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, but the remote nature and lack of required local privileges make exploitation likely in any multi‑user or SSE deployment where a client can invoke the vulnerable attachment upload functions. The vulnerability is not listed in the CISA KEV catalog, but its potential for cross‑tenant data leakage makes it a substantial risk for exposed or shared MCP instances.

Generated by OpenCVE AI on September 20, 2026 at 22:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to MCP Atlassian v0.22.0 or later to eliminate the unsupported file‑path logic
  • Restrict the use of the confluence_upload_attachment, confluence_upload_attachments, and jira_update_issue features to trusted users only and enforce role‑based access controls
  • If an upgrade cannot be performed immediately, isolate the MCP service from untrusted networks and limit write‑tool permissions to prevent unauthorized file reading

Generated by OpenCVE AI on September 20, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Sooperset
Sooperset mcp-atlassian
Vendors & Products Sooperset
Sooperset mcp-atlassian

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassian/confluence/attachments.py upload_attachment, and the jira_update_issue attachments parameter reaches src/mcp_atlassian/jira/attachments.py upload_attachment, without confining either path to an approved server workspace. In a remote HTTP, SSE, or multi-user deployment, absolute or traversing paths are resolved on the MCP server and uploaded to Atlassian, allowing a client with write-tool access to disclose server files, environment-held Atlassian credentials, or another tenant's data. A local single-user stdio deployment does not cross this trust boundary because the server runs in the caller's environment. This issue is fixed in version 0.22.0.
Title MCP Atlassian: Arbitrary server-side file read via attachment upload
Weaknesses CWE-22
CWE-73
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Sooperset Mcp-atlassian
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T16:10:16.281Z

Reserved: 2026-08-12T19:00:33.735Z

Link: CVE-2026-73496

cve-icon Vulnrichment

Updated: 2026-09-16T16:10:08.884Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:16:50.833

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-73496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path