MCPA-2026-0031
highpath-traversalCVSS 7.7
mcp-atlassian arbitrary file read via confluence_upload_attachment path
mcp-atlassian (PyPI) before 0.22.0: confluence_upload_attachment passes file_path directly to open(file_path, 'rb') with no path validation. Any authenticated MCP client — or a prompt-injected agent — can read any file the server process can access and exfiltrate it to Confluence as an attachment. Fixed in 0.22.0.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | mcp-atlassian | >= 0, < 0.22.0 |
Identifiers
GHSA-g5r6-gv6m-f5jvCWE-22
References
- advisory https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-g5r6-gv6m-f5jv
- fix https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
- web https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
Timeline
- Published: 2026-07-10