CVE-2026-77269

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
6.5
MEDIUM

Description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects download destinations but does not constrain source paths used by attachment uploads. A caller can provide an absolute or traversal file_path and cause the server to upload the selected local file. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and CVE-2026-27825, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

Published
September 22, 2026 7:16 PM
Last Modified
September 22, 2026 7:16 PM
Source
[email protected]

Weaknesses (CWE)

CWE-22

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.