PatchSiren cyber security CVE debrief
CVE-2026-77253 sooperset CVE debrief
A vulnerability in MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, allows disclosure of configuration, credentials, and other sensitive files readable by the MCP process. The issue, fixed in version 0.22.0, arises from the acceptance of arbitrary local filesystem paths in Jira and Confluence attachment upload tools. This vulnerability can lead to potential disclosure of sensitive information, including configuration and credentials, and may allow an attacker to cross the client-to-server filesystem boundary. Defenders should assess exposure and prioritize remediation to prevent potential security breaches.
- Vendor
- sooperset
- Product
- mcp-atlassian
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-28
Who should care
Defenders of HTTP or multi-user deployments using MCP Atlassian should assess exposure and prioritize remediation to prevent potential security breaches. This includes reviewing filesystem access controls, upgrading to version 0.22.0, and monitoring for suspicious attachment uploads. Security teams and vulnerability management teams should also be aware of the potential risks and take necessary actions to protect their systems.
Why it matters
Defenders should prioritize verifying exposure in HTTP or multi-user deployments, reviewing filesystem access controls, and upgrading to version 0.22.0 to prevent potential disclosure of sensitive information.
- Potential disclosure of configuration and credentials
- Possible exposure of mounted secrets or other sensitive files
- Verification of filesystem access controls is necessary
- Upgrade to version 0.22.0 to remediate the vulnerability
Technical summary
MCP Atlassian, a Model Context Protocol (MCP) server for Atlassian products, is vulnerable to disclosure of configuration, credentials, and other sensitive files readable by the MCP process. The issue arises from the acceptance of arbitrary local filesystem paths in Jira and Confluence attachment upload tools, allowing a caller to cross the client-to-server filesystem boundary. This vulnerability can lead to potential disclosure of sensitive information, including configuration and credentials. The issue is fixed in version 0.22.0.
Defensive priority
Defenders should prioritize verifying exposure in HTTP or multi-user deployments, reviewing filesystem access controls, and upgrading to version 0.22.0.
Recommended defensive actions
- Verify exposure in HTTP or multi-user deployments
- Review filesystem access controls
- Upgrade to version 0.22.0
- Monitor for suspicious attachment uploads
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The advisory provides details on the vulnerable input and processing flow through jira_upload_attachment, confluence_upload_attachment, file_path, and server-local filesystem. It also notes that the issue is fixed in version 0.22.0 and that defenders should verify exposure in HTTP or multi-user deployments, review filesystem access controls, and upgrade to the latest version to prevent potential disclosure of sensitive information. The advisory includes information on the affected entry points, controls, and code paths.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77253 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77253
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77253 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77253
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/pull/1448
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-vc25-24vv-fxxm
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.