GHSA-f26r-j276-ggg4: MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
Summary
The upload attachment tools in MCP Atlassian (a system that connects AI assistants to Atlassian software) accept file paths without validation, allowing an authenticated user or an AI tricked via prompt injection (hidden instructions in text) to read and upload any file from the server to Confluence or Jira. The code has a validate_safe_path function that protects downloads but does not use it for uploads, creating a security gap.
Vulnerability Details
EPSS: 0.0%
Yes
September 22, 2026
Classification
Taxonomy References
Affected Vendors
Affected Packages
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
Original source: https://github.com/advisories/GHSA-f26r-j276-ggg4
First tracked: September 22, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 92%