CVE-2026-77270
6.5 MEDIUMpublic exploit availablePublished 2026-09-22 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths. The server opens the selected file and uploads it to an Atlassian issue or page, allowing an MCP caller with upload access to disclose any file readable by the server process. The advisory traces the vulnerable input and processing flow through confluence_upload_attachment, jira_upload_attachment, file_path, and open(file_path, "rb"), which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-22
Vendors
mcp-atlassian
Products
mcp atlassian
Public exploit & PoC references
- https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460[Patch]
- https://github.com/sooperset/mcp-atlassian/pull/1448[Issue Tracking, Patch]
- https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0[Release Notes]
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-f26r-j276-ggg4[Exploit, Mitigation, Vendor Advisory]
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-f26r-j276-ggg4[Exploit, Mitigation, Vendor Advisory]
All references
- https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
- https://github.com/sooperset/mcp-atlassian/pull/1448
- https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-f26r-j276-ggg4
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-f26r-j276-ggg4
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2017-20284
- MEDIUMCVE-2024-58386PoC
- MEDIUMCVE-2025-1280
- HIGHCVE-2025-1281
- HIGHCVE-2025-14753
- HIGHCVE-2026-100372PoC
- HIGHCVE-2026-100520PoC
- MEDIUMCVE-2026-100533PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.