← Back to search

CVE-2026-77271

8.8 HIGHpublic exploit available

Published 2026-09-22 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows attackers to write files within the working directory, potentially leading to code execution by importing the modified module.
Exploitability
Exploitation is relatively easy as it requires an attacker to manipulate file writes within the working directory. Precondition is access to the Confluence attachment call sites.
Blast radius
If exploited, the impact could be severe, allowing for code execution within the application, potentially leading to full system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 0.22.0 or later.
rcecode-executionfile-writewebpatch

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its base directory to os.getcwd(), and affected Confluence attachment call sites omit base_dir, allowing attacker-selected writes within the working directory. This Python module overwrite can provide code execution when the application later imports the modified module, bypassing the remediation tracked as CVE-2026-27825. This issue is fixed in version 0.22.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22, CWE-94

Vendors

mcp-atlassian

Products

mcp atlassian

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.