MCP Atlassian Security Update Addresses 25 Vulnerabilities

P1 — VALIDATE AND UPDATEMedium to Critical · 5.3 / 5.4 / 5.5 / 5.9 / 6.1 / 6.5 / 7.1 / 7.4 / 7.7 / 8.3 / 8.6 / 8.8 / 10 (official CVSS v3/v4 scores)EXPLOITATION: NOT STATED

Quick Answer

The authority published GHSA-cc5h-2pwp-pvcc for MCP Atlassian packages and release streams identified in the project advisories. The project published 25 security advisories: MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport; MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path; MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud); MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files; MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue; MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass; MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths; MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira); MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825); MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call; MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow; MCP Atlassian: Arbitrary File Read via Upload Attachment Tools; MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches; MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials; MCP Atlassian: Insecure File Permissions on OAuth Token Storage; MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4); MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler; mcp-atlassian has an incomplete SSRF remediation; MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4); MCP Atlassian: SSRF Protection Bypass; [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token; MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters; MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup; MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions; MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path() Affected deployments should be matched to the authority's exact scope and moved to the supported fixed release.

Confirm Scope And Apply The Supported Fix

What to do now: Inventory MCP Atlassian packages and release streams identified in the project advisories, match the exact affected release or feature, apply the authority-supported fixed build or service remediation, validate the dependent workflow, and preserve evidence.

Open the authoritative advisory

Last verified: 2026-09-23 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeMCP Atlassian packages and release streams identified in the project advisories
AdvisoryGHSA-cc5h-2pwp-pvcc / GHSA-wv8v-v4c5-v75j / GHSA-w66g-j6c4-hcfc / GHSA-vc25-24vv-fxxm / GHSA-2xj6-xx86-cwwc / GHSA-3r68-hf9h-887v / GHSA-mrq8-fv7v-hhjg / GHSA-f4p7-qx46-wc5j / GHSA-h7wj-5v37-59r2 / GHSA-mfv2-4wvm-9pgp / GHSA-49xv-9743-pw8w / GHSA-f26r-j276-ggg4 / GHSA-6529-c226-h328 / GHSA-6cr4-ccf3-x7h4 / GHSA-4596-2p6p-28cv / GHSA-p6hp-93wp-fh6p / GHSA-g2r2-3j32-j27x / GHSA-5wf4-jqxh-8gm3 / GHSA-6vmq-24h2-pj7j / GHSA-hgcf-4mq8-5266 / GHSA-wrhw-j3f9-8vc6 / GHSA-f6pj-qv47-g96w / GHSA-v9m3-wfh8-5646 / GHSA-g5xv-mhgm-v5f6 / GHSA-93xw-j965-9mx3
CVEsCVE-2026-77243, CVE-2026-77244, CVE-2026-77246, CVE-2026-77247, CVE-2026-77248, CVE-2026-77249, CVE-2026-77250, CVE-2026-77251, CVE-2026-77253, CVE-2026-77255, CVE-2026-77257, CVE-2026-77258, CVE-2026-77259, CVE-2026-77260, CVE-2026-77261, CVE-2026-77262, CVE-2026-77265, CVE-2026-77266, CVE-2026-77267, CVE-2026-77268, CVE-2026-77269, CVE-2026-77270, CVE-2026-77271, CVE-2026-77272, CVE-2026-77274
Authoritative release date2026-09-22 20:34:43 UTC
Authority revision date2026-09-22 20:36:39 UTC
Affected versionsmcp-atlassian < 0.22.0
Fixed versionmcp-atlassian 0.22.0
CVSS base score5.3 / 5.4 / 5.5 / 5.9 / 6.1 / 6.5 / 7.1 / 7.4 / 7.7 / 8.3 / 8.6 / 8.8 / 10 (official CVSS v3/v4 scores)
CVSS severityMedium to Critical
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

The project published 25 security advisories: MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport; MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path; MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud); MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files; MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue; MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass; MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths; MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira); MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825); MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call; MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow; MCP Atlassian: Arbitrary File Read via Upload Attachment Tools; MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches; MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials; MCP Atlassian: Insecure File Permissions on OAuth Token Storage; MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4); MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler; mcp-atlassian has an incomplete SSRF remediation; MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4); MCP Atlassian: SSRF Protection Bypass; [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token; MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters; MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup; MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions; MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()

What To Validate Now

  1. Inventory. Locate MCP Atlassian packages and release streams identified in the project advisories deployments, versions, enabled features, exposure paths, owners, and dependent services.
  2. Establish applicability. Compare each deployment with the authority's affected-version statement: mcp-atlassian < 0.22.0 Do not infer applicability from product family or severity alone.
  3. Remediate. Apply mcp-atlassian 0.22.0 through the supported vendor or project channel, following the current advisory and change-control requirements.
  4. Validate. Confirm the resulting version or managed-service state, exercise representative functionality and recovery paths, monitor for regressions, and document exceptions.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Use the exact supported release stream and repository. Test dependencies, clusters, integrations, and rollback before broad deployment; a CVSS rating or reachable feature is not evidence of exploitation.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.