MCPA-2026-0030
highpath-traversalCVSS 7.7
mcp-atlassian arbitrary server-side file read via Jira attachment upload
mcp-atlassian (PyPI) before 0.22.0 passes the client-supplied file_path of the Jira attachment-upload tools directly to open() on the server's filesystem. Any authenticated MCP client — or an AI agent manipulated via prompt injection — can read arbitrary files the server process can access and exfiltrate them as Atlassian attachments. Fixed in 0.22.0.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | mcp-atlassian | >= 0, < 0.22.0 |
Identifiers
GHSA-wm45-qh3g-v83fCWE-22CWE-73
References
- advisory https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-wm45-qh3g-v83f
- web https://github.com/advisories/GHSA-wm45-qh3g-v83f
Timeline
- Published: 2026-07-10