CVE-2026-77258
mcp-atlassian: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-77258)
Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data readable by the server process. This issue is fixed in version 0.22.0.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
0.10.00.10.10.10.20.10.30.10.40.10.50.10.60.1.10.1.100.11.00.1.110.11.10.11.100.11.110.11.120.1.120.11.20.11.2a20.1.130.11.30.1.140.11.40.1.150.11.50.1.160.11.60.11.70.11.80.11.90.1.20.12.00.1.30.13.00.13.10.1.40.14.00.14.10.14.20.14.30.15.00.1.60.16.00.16.10.1.70.17.00.1.80.18.00.18.1Metrics
Show all metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
References & sources
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-93xw-j965-9mx3x_refsource_CONFIRM
- https://github.com/sooperset/mcp-atlassian/pull/1448x_refsource_MISC
- https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460x_refsource_MISC
- https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-77258advisory
- https://github.com/sooperset/mcp-atlassianpackage
- https://pypi.org/project/mcp-atlassianpackage
- https://github.com/advisories/GHSA-93xw-j965-9mx3advisory
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-29 14:01 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:mcp-atlassian:mcp_atlassian:*:*:*:*:*:*:*:* versions up to (excluding) 0.22.0
- Reference Type: GitHub, Inc.: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460 Types: Patch
- Reference Type: GitHub, Inc.: https://github.com/sooperset/mcp-atlassian/pull/1448 Types: Issue Tracking, Patch
- Reference Type: GitHub, Inc.: https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0 Types: Release Notes
- CVE Modified2026-09-26 00:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-93xw-j965-9mx3
- SSVC: {"id":"CVE-2026-77258","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalIm…
- New CVE Received2026-09-22 18:17 UTC· security-advisories@github.com
- Description: MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data readable by the server process. This issue is fixed in version 0.22.0.
- CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- CWE: CWE-22
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/77xxx/CVE-2026-77258.json">CVE-2026-77258</a>