Impact
The vulnerability resides in the MCP Atlassian server, where unauthenticated calls to the streamable HTTP transport bypass user identity checks and the upload_attachment endpoint accepts an unrestricted file_path parameter. This combination allows an attacker to read any file accessible to the MCP process, upload the contents to a Jira issue or Confluence page, and later retrieve the file through the interface. The flaw results in confidentiality compromise, enabling disclosure of sensitive data stored on the server.
Affected Systems
Affected users run the sooperset:mcp-atlassian product on Atlassian Confluence or Jira environments with a version earlier than 0.22.0. The advisory specifically mentions that the issue is fixed in release v0.22.0, so any installation that has not yet been upgraded is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. No EPSS score is reported, so the exploitation probability cannot be quantified at this time, but the flaw can be used by an unauthenticated network caller to access arbitrary files. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are currently known. Nonetheless, because the attack can be performed over the network without authentication, the risk remains significant for environments using the vulnerable version.
OpenCVE Enrichment
Github GHSA