CyberRota Analysis
AI-GeneratedThe vulnerability allows a permitted Confluence MCP caller to upload arbitrary files as attachments, potentially disclosing sensitive server-readable data due to insufficient file path restrictions. Organizations using affected versions of the MCP server for Confluence and Jira should prioritize upgrading to version 0.22.0 to mitigate this high-severity risk. Immediate action is recommended to prevent unauthorized data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data readable by the server process. This issue is fixed in version 0.22.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)