Impact
MCP Atlassian, a protocol server for Atlassian’s Confluence and Jira, contains a flaw whereby HTTP‑exposed upload tools accept a user supplied file_path and pass it directly to local file system operations. This allows an attacker with tool access to supply an arbitrary path, causing the server to read any local file and upload its contents as an Atlassian attachment. The vulnerability is a classic file‑path traversal leading to disclosure of sensitive files.
Affected Systems
The vulnerability affects the MCP Atlassian server provided by sooperset. Versions before 0.22.0 of the product are impacted. The server is used in environments running Atlassian Confluence or Jira.
Risk and Exploitability
The flaw has a CVSS score of 8.3, indicating high severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. The attacker can exploit the weakness remotely via the HTTP API, leveraging the upload tools without needing local access. Successful exploitation results in unauthorized reading of arbitrary local files and their exposure as attachments within the Atlassian platform.
OpenCVE Enrichment