Executive brief
MCP Atlassian is a server that integrates AI assistants with Atlassian collaboration tools like Jira and Confluence. In multi-user or remote deployments, attackers with write access to the attachment tools could upload files from arbitrary locations on the server (using absolute paths or directory traversal sequences), potentially exposing sensitive files, credentials stored in environment variables, or data from other tenants. Single-user local deployments are not affected due to trust boundaries.
Technical details
A path traversal vulnerability exists in the `confluence_upload_attachment`, `confluence_upload_attachments`, and `jira_update_issue` tools (via the `attachments` parameter). Client-supplied file paths are passed directly to `upload_attachment` functions in `src/mcp_atlassian/confluence/attachments.py` and `src/mcp_atlassian/jira/attachments.py` without validation against the server's workspace directory. An attacker with write-tool access in HTTP, SSE, or multi-user deployments can provide absolute paths or traversal sequences (e.g., `../../../etc/passwd`) to read and exfiltrate arbitrary server files, including credentials and tenant data. The fix, deployed in version 0.22.0, introduces a `validate_safe_path` function that confines all file paths to the server's working directory before opening files.
Affected products
- MCP Atlassian MCP Atlassian prior to 0.22.0
Timeline
- 2026-09-14: disclosed
- 2026-07-10: patched: Fix merged in version 0.22.0