mcp-atlassian is vulnerable to Arbitrary File Read
77
High Risk
The Jira and Confluence attachment upload tools treat a caller-controlled file_path as a server-local path and read it with the server process's privileges before uploading it as an attachment. In HTTP or multi-user deployments the caller and the server filesystem are separate trust boundaries, so a client with upload access can cause disclosure of arbitrary server-local files such as configuration and secrets. Exploitation is deterministic and does not depend on model behavior. The fix constrains upload paths with a safe-path check and rejects unsafe path forms.
You are affected if you are using a version that falls within the vulnerable range and you expose the attachment upload tools over the HTTP or SSE transport to untrusted callers.
mcp-atlassian is vulnerable to Arbitrary File Read in versions 0.0.1 - 0.21.1.
Upgrade the mcp-atlassian library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant