mcp-atlassian is vulnerable to Authentication Bypass
100
Critical Risk
The HTTP transport's AtlassianOpaqueTokenVerifier accepts any non-empty bearer token, and when no OAuth proxy is configured the server does not reject requests that omit the Authorization header. Tool handlers then fall back to the operator's environment-configured Atlassian credentials. A network client that can reach the streamable-http endpoint can invoke Jira and Confluence tools as the operator without any valid credential. The fix rejects unauthenticated requests at the transport boundary and gates the global-credential fallback behind an explicit opt-in.
You are affected if you are using a version that falls within the vulnerable range and you expose the HTTP (streamable-http or SSE) transport with server-side Atlassian credentials configured.
mcp-atlassian is vulnerable to Authentication Bypass in versions 0.0.1 - 0.21.1.
Upgrade the mcp-atlassian library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant