mcp-atlassian is vulnerable to Arbitrary File Read
86
High Risk
The attachment upload tools pass a caller-supplied file_path straight into open() with no path validation, while the streamable-http transport does not require authentication by default. An unauthenticated client can upload an arbitrary server-local file such as /proc/self/environ or an .env file to an attacker-chosen page or issue and read it back, disclosing operator secrets. The two weaknesses chain into unauthenticated arbitrary file read on the server host. The fix validates upload paths and requires authentication on the HTTP transport.
You are affected if you are using a version that falls within the vulnerable range and you run the streamable-http or SSE transport reachable by untrusted clients.
mcp-atlassian is vulnerable to Arbitrary File Read in versions 0.0.1 - 0.21.1.
Upgrade the mcp-atlassian library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant