Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f4p7-qx46-wc5j | MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira) |
Tue, 29 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mcp-atlassian
Mcp-atlassian mcp Atlassian |
|
| CPEs | cpe:2.3:a:mcp-atlassian:mcp_atlassian:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mcp-atlassian
Mcp-atlassian mcp Atlassian |
|
| Metrics |
cvssV3_1
|
Sat, 26 Sep 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sooperset
Sooperset mcp-atlassian |
|
| Vendors & Products |
Sooperset
Sooperset mcp-atlassian |
Tue, 22 Sep 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept an unconstrained file_path and open the referenced server-local file. A permitted MCP caller can upload sensitive host files to an Atlassian destination and then retrieve their contents. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and CVE-2026-27825, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0. | |
| Title | MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira) | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-25T23:59:28.621Z
Reserved: 2026-08-20T19:02:23.417Z
Link: CVE-2026-77260
Updated: 2026-09-25T23:59:24.600Z
Status : Analyzed
Published: 2026-09-22T18:17:18.347
Modified: 2026-09-29T13:56:16.277
Link: CVE-2026-77260
No data.
OpenCVE Enrichment
Updated: 2026-09-22T20:00:11Z
Github GHSA