CVE-2026-77251
- EPSS 0.25%
- Veröffentlicht 22.09.2026 17:55:37
- Zuletzt bearbeitet 29.09.2026 14:21:29
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence search uses an ...
CVE-2026-77252
- EPSS 0.42%
- Veröffentlicht 22.09.2026 17:54:02
- Zuletzt bearbeitet 25.09.2026 17:39:10
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, caller-supplied projects_filter and spaces_filter arguments can replace administrator-configured allowlists, and caller-provided pro...
CVE-2026-77267
- EPSS 0.34%
- Veröffentlicht 22.09.2026 17:52:25
- Zuletzt bearbeitet 29.09.2026 18:59:56
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and used to constru...
CVE-2026-77250
- EPSS 0.12%
- Veröffentlicht 22.09.2026 17:51:02
- Zuletzt bearbeitet 29.09.2026 14:22:55
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian directory using pr...
- EPSS 0.28%
- Veröffentlicht 22.09.2026 17:49:38
- Zuletzt bearbeitet 29.09.2026 15:17:49
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to the operator'...
CVE-2026-77265
- EPSS 0.26%
- Veröffentlicht 22.09.2026 17:47:58
- Zuletzt bearbeitet 29.09.2026 19:00:07
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again for the connec...
CVE-2026-77270
- EPSS 0.4%
- Veröffentlicht 22.09.2026 17:46:30
- Zuletzt bearbeitet 28.09.2026 13:35:22
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths. The server o...
CVE-2026-77258
- EPSS 0.33%
- Veröffentlicht 22.09.2026 17:39:28
- Zuletzt bearbeitet 29.09.2026 14:01:18
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server...
CVE-2026-77274
- EPSS 0.47%
- Veröffentlicht 22.09.2026 17:36:49
- Zuletzt bearbeitet 28.09.2026 13:41:36
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf has a backslash authority confusion because it interprets the authority differently from the Requests connecti...
CVE-2026-73497
- EPSS 0.23%
- Veröffentlicht 14.09.2026 19:50:23
- Zuletzt bearbeitet 30.09.2026 17:51:56
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url header host once...