mcp-atlassian is vulnerable to Server-Side Request Forgery (SSRF)
75
High Risk
The SSRF validation for caller-supplied Atlassian URL headers resolves and checks the destination host with getaddrinfo, but the outbound request re-resolves the host at connect time without pinning the validated address. A time-based DNS rebinding domain can present a public address during validation and a private or metadata address at connection, bypassing the check. An unauthenticated client on the multi-user HTTP transport can reach internal or cloud-metadata endpoints. The fix pins the validated IP for the connection and re-pins across redirects.
You are affected if you are using a version that falls within the vulnerable range and you run the multi-user HTTP transport that accepts caller-supplied Atlassian URL headers.
mcp-atlassian is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 0.21.1.
Upgrade the mcp-atlassian library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant