mcp-atlassian is vulnerable to Improper Authorization
88
High Risk
The ENABLED_TOOLS and toolset filters are applied only when listing tools, while the tools/call handler dispatches from the full unfiltered tool registry. A client that knows a tool name can invoke any registered tool, including write and delete operations, regardless of the configured allowlist. This defeats least-privilege configurations on multi-user HTTP deployments. The fix enforces the tool authorization filters at dispatch time, not just at listing time.
You are affected if you are using a version that falls within the vulnerable range and you rely on ENABLED_TOOLS or toolset filtering as an access-control boundary on the HTTP transport.
mcp-atlassian is vulnerable to Improper Authorization in versions 0.0.1 - 0.21.1.
Upgrade the mcp-atlassian library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant