MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence attachment upload tools accept arbitrary local filesystem paths and send the selected bytes to Atlassian. In HTTP or multi
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| sooperset | mcp-atlassian | < 0.22.0 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| sooperset | mcp-atlassian | < 0.22.0 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-77244 | 10.0 CRITICAL | [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier acce |
| CVE-2026-77254 | 9.1 CRITICAL | MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Conf |
| CVE-2026-77274 | 8.8 HIGH | MCP Atlassian: SSRF Protection Bypass |
| CVE-2026-77243 | 8.8 HIGH | MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass |
| CVE-2026-77255 | 8.6 HIGH | MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue |
| CVE-2026-77262 | 8.6 HIGH | MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP to |
| CVE-2026-77248 | 8.6 HIGH | MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, |
| CVE-2026-77247 | 8.3 HIGH | MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unres |
| CVE-2026-77260 | 8.3 HIGH | MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment |
| CVE-2026-77257 | 8.3 HIGH | MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths |
| CVE-2026-77267 | 8.3 HIGH | mcp-atlassian has an incomplete SSRF remediation |
| CVE-2026-77271 | 8.3 HIGH | MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (by |
| CVE-2026-77251 | 8.3 HIGH | MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project con |
| CVE-2026-77256 | 8.3 HIGH | MCP Atlassian: OAuth refresh-token backup file is world-readable under default Unix umask |
| CVE-2026-77259 | 7.7 HIGH | MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of |
| CVE-2026-77258 | 7.7 HIGH | MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_saf |
| CVE-2026-77242 | 7.5 HIGH | MCP Atlassian: Incomplete fix for CVE-2026-27826: DNS rebinding bypasses SSRF validation ( |
| CVE-2026-77246 | 7.4 HIGH | MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment U |
| CVE-2026-77261 | 7.1 HIGH | MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication br |
| CVE-2026-77269 | 6.5 MEDIUM | MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete |
显示前 20 条,共 29 条。 查看全部 → →
暂无评论