Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluence/attachments.py through _upload_attachment_direct() without calling validate_safe_path. An authenticated MCP client can read any file accessible to the server process and exfiltrate it to Confluence as an attachment. If an AI agent can be induced to call the tool through untrusted content, the same flaw can disclose server environment variables such as CONFLUENCE_API_TOKEN and other credentials. This issue is fixed in version 0.22.0. Join the discussion | CVE Database V5 | 08/12/2026, 21:17:24 UTC Added: 08/12/2026, 21:26:44 UTC |
0 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `download_path` parameter that is written to without any directory boundary enforcement. An attacker who can call this tool and supply or access a Confluence attachment with malicious content can write arbitrary content to any path the server process has write access to. Because the attacker controls both the write destination and the written content (via an uploaded Confluence attachment), this constitutes for arbitrary code execution (for example, writing a valid cron entry to `/etc/cron.d/` achieves code execution within one scheduler cycle with no server restart required). Version 0.17.0 fixes the issue. Join the discussion | CVE Database V5 | 03/10/2026, 18:53:41 UTC Added: 03/10/2026, 19:30:04 UTC |
0 CVE-2026-27826 is a high-severity Server-Side Request Forgery (SSRF) vulnerability in sooperset's mcp-atlassian server versions prior to 0.17.0. It allows unauthenticated attackers who can access the HTTP endpoint to force the server to make arbitrary outbound HTTP requests by supplying two custom headers without needing an Authorization header. This vulnerability resides in the HTTP middleware and dependency injection layer, bypassing tool-level code detection. In cloud environments, it can lead to theft of IAM role credentials via the instance metadata service. In any deployment, it enables internal network reconnaissance and injection of attacker-controlled content into LLM tool results. The issue is fixed in version 0.17.0. Join the discussion | CVE Database V5 | 03/10/2026, 18:46:12 UTC Added: 03/10/2026, 18:59:55 UTC |
Showing 1 to 3 of 3 results