MinorCritical vulnerability
CVE-2026-77258 (CVSS 7.7)
NVD · officialPublished Sep 22, 2026Risk 23/100EPSS 0.3%
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data readable by the server process. This issue is fixed in version 0.22.0.
Technical details
CVSS
7.7
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:NoneA:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source