CVE-2026-77258

mcp-atlassian: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-77258)

Description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data readable by the server process. This issue is fixed in version 0.22.0.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

pypimcp-atlassian
0.10.00.10.10.10.20.10.30.10.40.10.50.10.60.1.10.1.100.11.00.1.110.11.10.11.100.11.110.11.120.1.120.11.20.11.2a20.1.130.11.30.1.140.11.40.1.150.11.50.1.160.11.60.11.70.11.80.11.90.1.20.12.00.1.30.13.00.13.10.1.40.14.00.14.10.14.20.14.30.15.00.1.60.16.00.16.10.1.70.17.00.1.80.18.00.18.1

Metrics

7.7
Source: cna-v3
25.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-01 16:38 UTC
CWE-22

Weakness classes (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-09-29 14:01 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:mcp-atlassian:mcp_atlassian:*:*:*:*:*:*:*:* versions up to (excluding) 0.22.0
    • Reference Type: GitHub, Inc.: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460 Types: Patch
    • Reference Type: GitHub, Inc.: https://github.com/sooperset/mcp-atlassian/pull/1448 Types: Issue Tracking, Patch
    • Reference Type: GitHub, Inc.: https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0 Types: Release Notes
  2. CVE Modified2026-09-26 00:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-93xw-j965-9mx3
    • SSVC: {"id":"CVE-2026-77258","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalIm…
  3. New CVE Received2026-09-22 18:17 UTC· security-advisories@github.com
    • Description: MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data readable by the server process. This issue is fixed in version 0.22.0.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
    • CWE: CWE-22
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/77xxx/CVE-2026-77258.json">CVE-2026-77258</a>