CVE-2026-77266: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in sooperset mcp-atlassian
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences without constraining the resolved path to the server workspace. An MCP caller with attachment access can read a chosen server-local file and exfiltrate it through Jira or Confluence. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and path traversal, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
AI Analysis
Technical Summary
The vulnerability in sooperset mcp-atlassian (a Model Context Protocol server for Atlassian products) arises from improper limitation of pathname to a restricted directory (CWE-22). Specifically, the upload_attachment function accepts absolute paths and path traversal sequences without constraining the resolved file path to the server workspace. This flaw enables an attacker with attachment access to read arbitrary files on the server and exfiltrate their contents via Jira or Confluence. The vulnerable code paths include upload_attachment and file_path processing. The vulnerability is addressed in version 0.22.0.
Potential Impact
An attacker with attachment access to the MCP server can read arbitrary files on the server filesystem outside the intended workspace directory. This leads to confidentiality loss (high impact on confidentiality) but does not affect integrity or availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Upgrade sooperset mcp-atlassian to version 0.22.0 or later, where this path traversal vulnerability is fixed. No other mitigations are indicated by the vendor advisory.
CVE-2026-77266: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in sooperset mcp-atlassian
Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences without constraining the resolved path to the server workspace. An MCP caller with attachment access can read a chosen server-local file and exfiltrate it through Jira or Confluence. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and path traversal, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
CVSS v3.1
Score 6.5medium
Affected software
sooperset
mcp-atlassian
pkg:github/sooperset/mcp-atlassianRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in sooperset mcp-atlassian (a Model Context Protocol server for Atlassian products) arises from improper limitation of pathname to a restricted directory (CWE-22). Specifically, the upload_attachment function accepts absolute paths and path traversal sequences without constraining the resolved file path to the server workspace. This flaw enables an attacker with attachment access to read arbitrary files on the server and exfiltrate their contents via Jira or Confluence. The vulnerable code paths include upload_attachment and file_path processing. The vulnerability is addressed in version 0.22.0.
Potential Impact
An attacker with attachment access to the MCP server can read arbitrary files on the server filesystem outside the intended workspace directory. This leads to confidentiality loss (high impact on confidentiality) but does not affect integrity or availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Upgrade sooperset mcp-atlassian to version 0.22.0 or later, where this path traversal vulnerability is fixed. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-20T19:14:21.330Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab2cd74f7a7c54106997ea2
Added to database: 09/22/2026, 18:48:20 UTC
Last enriched: 09/22/2026, 19:03:15 UTC
Last updated: 09/23/2026, 01:58:06 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.