GHSA-p6hp-93wp-fh6p: MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
Summary
The `mcp-atlassian` tool has a path traversal vulnerability (CWE-22, a weakness that lets attackers access files outside intended directories) in its `confluence_upload_attachment` function. An attacker can read any file the server can access by passing an arbitrary file path, then upload that file to an attacker-controlled server. This is especially dangerous because the default setup exposes the tool over the network without authentication, making it remotely exploitable.
Vulnerability Details
EPSS: 0.0%
Yes
September 22, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-p6hp-93wp-fh6p
First tracked: September 22, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 92%