Junglewise Threat Intelligence

sooperset mcp-atlassian path traversal in confluence_upload_attachment

Severity: high · CVSS 7.7 · Published 2026-07-10

Technologies: Sooperset Mcp-Atlassian, mcp-atlassian (PyPI). Vendors: Sooperset, PyPI.

Executive brief

A vulnerability in the mcp-atlassian library allows unauthorized access to sensitive files on the server where the software is running. This library is used to connect AI agents and Model Context Protocol (MCP) clients to Atlassian services like Confluence. An attacker can exploit this to steal critical data, such as API tokens, AWS keys, and database credentials, potentially leading to a full takeover of connected Atlassian accounts.

Technical details

A path traversal vulnerability (CWE-22) exists in mcp-atlassian due to missing path validation in the `confluence_upload_attachment` tool. The `_upload_attachment_direct()` function in `src/mcp_atlassian/confluence/attachments.py` passes a user-provided `file_path` directly to the Python `open()` function. An authenticated MCP client or an AI agent targeted by prompt injection can specify arbitrary system paths (e.g., `/proc/self/environ` or SSH keys). The server then reads these files and uploads them to Confluence as attachments, exfiltrating sensitive data. This has been patched in version 0.22.0 by implementing `validate_safe_path()`.

Affected products

  • sooperset mcp-atlassian < 0.22.0

Timeline

  • 2026-07-10: advisory: GitHub Advisory GHSA-g5r6-gv6m-f5jv published
  • 2026-07-10: patched: Fix released in version 0.22.0

References

Related threats