GHSA-f6pj-qv47-g96w: MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
Summary
The MCP Atlassian tool for Jira and Confluence has a vulnerability where the file upload functions accept file paths controlled by the caller and read those files from the server's local filesystem before uploading them as attachments. This means an attacker using the tool can trick the server into reading and uploading any file the server process can access, especially in HTTP or multi-user deployments where the caller and server are separate security boundaries.
Vulnerability Details
EPSS: 0.0%
Yes
September 22, 2026
Classification
Taxonomy References
Affected Vendors
Affected Packages
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://github.com/advisories/GHSA-f6pj-qv47-g96w
First tracked: September 22, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 85%