{"data":{"id":"70ea13d5-ee25-47db-8e05-5e38650bd483","title":"GHSA-f26r-j276-ggg4: MCP Atlassian: Arbitrary File Read via Upload Attachment Tools","summary":"The upload attachment tools in MCP Atlassian (a system that connects AI assistants to Atlassian software) accept file paths without validation, allowing an authenticated user or an AI tricked via prompt injection (hidden instructions in text) to read and upload any file from the server to Confluence or Jira. The code has a validate_safe_path function that protects downloads but does not use it for uploads, creating a security gap.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-f26r-j276-ggg4","publishedAt":"2026-09-22T20:35:11.000Z","cveId":"CVE-2026-77270","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["prompt_injection","data_extraction"],"issueType":"vulnerability","affectedPackages":["mcp-atlassian@< 0.22.0 (fixed: 0.22.0)"],"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["Atlassian","MCP","Confluence","Jira"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-09-22T20:35:11.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0051"]}}