Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73496— MCP Atlassian: Arbitrary server-side file read via attachment upload

Quick assessment

Affected
sooperset mcp-atlassian
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MCP Atlassian 是一个面向 Atlassian 产品(Confluence 和 Jira)的模型上下文协议(MCP)服务器。在 0.22.0 之前, 和 工具会通过 中的 函数传递由客户端控制的 ,而 Jira 的 中的 参数也会经由 中的 函数处理,但这两个路径均未将文件路径限制在服务器端已批准的工作区范围内。在远程 HTTP、SSE 或多用户部署环境下,绝对路径或包含路径遍历的路径会在 MCP 服务器上解析并上传至 Atlassian,这使得拥有写工具访问权限的客户端能够泄露服务器上的文件、由环境变

CVSS 7.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73496

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MCP Atlassian: Arbitrary server-side file read via attachment upload
Source: CVE Program / CVE List V5
Vulnerability Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassian/confluence/attachments.py upload_attachment, and the jira_update_issue attachments parameter reaches src/mcp_atlassian/jira/attachments.py upload_attachment, without confining either path to an approved server workspace. In a remote HTTP, SSE, or multi-user deployment, absolute or traversing paths are resolved on the MCP server and uploaded to Atlassian, allowing a client with write-tool access to disclose server files, environment-held Atlassian credentials, or another tenant's data. A local single-user stdio deployment does not cross this trust boundary because the server runs in the caller's environment. This issue is fixed in version 0.22.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sooperset mcp-atlassian < 0.22.0 -

II. Public POCs for CVE-2026-73496

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73496

登录查看更多情报信息。

Patches & Fixes for CVE-2026-73496 (1)

Vendor Advisories for CVE-2026-73496 (1)

Vendor Pages for CVE-2026-73496 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-73496

No comments yet


Leave a comment