CVE-2026-73496
- EPSS 0.33%
- Veröffentlicht 14.09.2026 19:49:03
- Zuletzt bearbeitet 30.09.2026 17:51:56
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassia...
CVE-2026-73498
- EPSS 0.33%
- Veröffentlicht 12.08.2026 21:17:24
- Zuletzt bearbeitet 18.09.2026 20:09:01
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluence/...
CVE-2026-27826
- EPSS 13.63%
- Veröffentlicht 10.03.2026 18:46:12
- Zuletzt bearbeitet 13.04.2026 15:01:48
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, an unauthenticated attacker who can reach the mcp-atlassian HTTP endpoint can force the server process to make outbound HTTP...