Impact
Upload_attachment on MCP Atlassian can be supplied with absolute paths and traversal components, allowing a caller who has attachment upload permission to read any file located on the server’s filesystem. The data can then be exfiltrated back through the normal Jira or Confluence channels, resulting in a confidentiality breach. The weakness is a classic directory traversal flaw described by CWE‑22.
Affected Systems
Version <0.22.0 of the MCP Atlassian server, distributed by sooperset, is vulnerable. Deployments that interface with Atlassian Confluence or Jira and expose attachment upload functionality are affected. Users who hold the ability to upload attachments can trigger the flaw.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate severity. EPSS data is not available, and it is not listed in CISA’s KEV catalog. Exploitation requires authenticated attachment‑upload privileges; there is no indication of a publicly exploitable attack vector. Nevertheless, an attacker who can gain upload access could read arbitrary files and exfiltrate them.
OpenCVE Enrichment