Impact
MCP Atlassian servers process caller‑controlled file paths in the attachment upload tools without enforcing server‑local path restrictions. An attacker who can upload attachments gains the ability to read any file on the server that the process can access, potentially exposing sensitive configuration, credentials, or other data. The vulnerability is an example of an arbitrary file read flaw.
Affected Systems
The issue affects the SooperSet MCP Atlassian server, versions prior to 0.22.0. The vulnerability is present in the attachment upload features of Jira and Confluence integration modules within MCP Atlassian.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity. An exploit requires that the attacker has permission to upload attachments to an Atlassian issue or page via the MCP server. The vulnerability is not listed in the CISA KEV catalog and no EPSS score is available, suggesting limited publicly documented exploitation but a realistic possibility given user privileges. Attackers can potentially read any accessible file on the server, which could lead to confidentiality damage. Mitigation is straightforward once the upgrade path is applied.
OpenCVE Enrichment