External Control of File Name or Path Affecting mcp-atlassian package, versions [,0.22.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about External Control of File Name or Path vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-MCPATLASSIAN-17950785
  • published11 Jul 2026
  • disclosed10 Jul 2026
  • creditUnknown

Introduced: 10 Jul 2026

CVE NOT AVAILABLE CWE-22  (opens in a new tab)
CWE-73  (opens in a new tab)

How to fix?

Upgrade mcp-atlassian to version 0.22.0 or higher.

Overview

mcp-atlassian is a The Model Context Protocol (MCP) Atlassian integration is an open-source implementation that bridges Atlassian products (Jira and Confluence) with AI language models following Anthropic's MCP specification. This project enables secure, contextual AI interactions with Atlassian tools while maintaining data privacy and security. Key features include:

Affected versions of this package are vulnerable to External Control of File Name or Path via the upload_attachment process. An attacker can access and exfiltrate arbitrary files from the server's filesystem, including sensitive configuration and credential files, by supplying crafted file paths that are resolved and read on the server. This is only exploitable if the deployment uses remote or HTTP-based transports, as in local single-user deployments the file path refers to the user's own files.

CVSS Base Scores

version 4.0
version 3.1