CVE-2026-77250: CWE-312: Cleartext Storage of Sensitive Information in sooperset mcp-atlassian
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian directory using process-default permissions. On systems with a permissive umask, same-group or other local users and processes can read the persisted tokens and reuse the associated Atlassian access. The advisory traces the vulnerable input and processing flow through OAuthConfig._save_tokens, ~/.mcp-atlassian/oauth-<client_id>.json, access_token, and refresh_token, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
AI Analysis
Technical Summary
The vulnerability involves cleartext storage of OAuth access and refresh tokens by the OAuthConfig component in mcp-atlassian versions before 0.22.0. Tokens are saved in plaintext fallback files under the user's .mcp-atlassian directory with process-default permissions. On systems with permissive umask settings, other local users or processes in the same group can read these tokens and reuse the associated Atlassian access. The flaw is tracked through the OAuthConfig._save_tokens method and the oauth-<client_id>.json files. The issue is resolved in version 0.22.0.
Potential Impact
An attacker with local access to the affected system and the ability to read the user's .mcp-atlassian directory can obtain OAuth tokens in cleartext. This can lead to unauthorized access to Atlassian resources associated with those tokens. The confidentiality of the tokens is compromised, but integrity and availability impacts are limited.
Mitigation Recommendations
Upgrade mcp-atlassian to version 0.22.0 or later, where this issue is fixed. Until then, restrict file system permissions and umask settings to prevent unauthorized local users from reading the token files. No other vendor advisories or patches are noted.
CVE-2026-77250: CWE-312: Cleartext Storage of Sensitive Information in sooperset mcp-atlassian
Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian directory using process-default permissions. On systems with a permissive umask, same-group or other local users and processes can read the persisted tokens and reuse the associated Atlassian access. The advisory traces the vulnerable input and processing flow through OAuthConfig._save_tokens, ~/.mcp-atlassian/oauth-<client_id>.json, access_token, and refresh_token, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
CVSS v3.1
Score 6.1medium
Affected software
sooperset
mcp-atlassian
pkg:github/sooperset/mcp-atlassianRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves cleartext storage of OAuth access and refresh tokens by the OAuthConfig component in mcp-atlassian versions before 0.22.0. Tokens are saved in plaintext fallback files under the user's .mcp-atlassian directory with process-default permissions. On systems with permissive umask settings, other local users or processes in the same group can read these tokens and reuse the associated Atlassian access. The flaw is tracked through the OAuthConfig._save_tokens method and the oauth-<client_id>.json files. The issue is resolved in version 0.22.0.
Potential Impact
An attacker with local access to the affected system and the ability to read the user's .mcp-atlassian directory can obtain OAuth tokens in cleartext. This can lead to unauthorized access to Atlassian resources associated with those tokens. The confidentiality of the tokens is compromised, but integrity and availability impacts are limited.
Mitigation Recommendations
Upgrade mcp-atlassian to version 0.22.0 or later, where this issue is fixed. Until then, restrict file system permissions and umask settings to prevent unauthorized local users from reading the token files. No other vendor advisories or patches are noted.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-20T19:02:23.416Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab2c2eef7a7c541068b81cf
Added to database: 09/22/2026, 18:03:26 UTC
Last enriched: 09/22/2026, 18:18:53 UTC
Last updated: 09/23/2026, 01:58:06 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.