Junglewise Threat Intelligence

CVE-2026-73498: MCP Atlassian arbitrary file read in attachment upload

CVE-2026-73498 · Severity: high · CVSS 7.7 · Published 2026-08-12

Technologies: mcp-atlassian (PyPI), Sooperset Mcp-Atlassian. Vendors: PyPI, Sooperset.

Executive brief

MCP Atlassian is a server that allows AI agents and clients to integrate with Atlassian products like Confluence and Jira. A flaw in the file upload feature allows authenticated users to read any file accessible to the server process and steal it by uploading it as an attachment, potentially exposing sensitive credentials like API tokens stored in environment variables.

Technical details

The vulnerability is a path traversal / arbitrary file read in the confluence_upload_attachment function. The vulnerable code in src/mcp_atlassian/confluence/attachments.py passes client-supplied file_path directly to open(file_path, "rb") via _upload_attachment_direct() without calling validate_safe_path, allowing absolute paths or ../ traversal sequences. An authenticated MCP client can supply any file path accessible to the server process, causing the server to read and exfiltrate that file to Confluence as an attachment. If an AI agent can be induced to invoke this tool through untrusted content, attacker-controlled prompts can disclose sensitive environment variables such as CONFLUENCE_API_TOKEN. The fix in version 0.22.0 adds validate_safe_path validation to confine uploads to the working directory before file access.

Affected products

  • sooperset mcp-atlassian prior to 0.22.0

Timeline

  • 2026-08-12: disclosed
  • 2026-07-10: patched: Fix merged in version 0.22.0

References

Related threats