{"data":{"id":"882a03ad-84be-423b-8200-5f28614bbeb5","title":"CVE-2026-73498: MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, co","summary":"MCP Atlassian (a server that connects AI tools to Atlassian products like Confluence and Jira) had a vulnerability in versions before 0.22.0 where the confluence_upload_attachment function didn't properly validate file paths, allowing an authenticated attacker to read any file the server could access and upload it to Confluence. This could expose sensitive credentials like API tokens if an AI agent is tricked into using this function through untrusted input.","solution":"This issue is fixed in version 0.22.0.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73498","publishedAt":"2026-08-12T22:17:16.973Z","cveId":"CVE-2026-73498","cweIds":["CWE-22"],"cvssScore":"7.7","cvssSeverity":"high","severity":"high","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["MCP Atlassian","Atlassian","Confluence","Jira"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-12T22:17:16.973Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}