MCP Atlassian Vulnerabilities

pip AI Agents

AI Threat Alert tracks 39 known vulnerabilities in MCP Atlassian, 3 rated critical — an AI/ML ai agents in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
45
Risk Score
39
Total CVEs
3
Critical
pip
Ecosystem
Sep 22, 2026
Last CVE
85%
Patch Rate
4d
Avg Time to Patch

Known Vulnerabilities (36 total, page 2 of 2)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-77265 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again for the connection. An unauthenticated caller can use a DNS-rebinding hostname that returns a public address during validation and an internal address during connection, causing requests to internal or metadata services. The advisory traces the vulnerable input an 5.9 Sep 22, 2026 CRITICAL CVE-2026-77244 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to the operator's globally configured Jira or Confluence credentials. A network client that can reach the MCP endpoint can invoke Atlassian tools as the operator, including read and write operations available to that account. The advisory traces the vulnerable input 10.0 Sep 22, 2026 HIGH CVE-2026-77258 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data readable by the server process. This issue is fixed in version 0.22.0. 7.7 Sep 22, 2026 HIGH CVE-2026-77274 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf has a backslash authority confusion because it interprets the authority differently from the Requests connection layer in the header-based Jira and Confluence URL authentication flow. A crafted URL can validate as an external hostname while the HTTP client connects to an internal host, permitting server-side requests to protected network resources. This issu -- Sep 22, 2026 HIGH CVE-2026-73496 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassian/confluence/attachments.py upload_attachment, and the jira_update_issue attachments parameter reaches src/mcp_atlassian/jira/attachments.py upload_attachment, without confining either path to an approved server workspace. In a remote HTTP, SSE, or m 7.7 Sep 14, 2026 MEDIUM CVE-2026-73497 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0, validate_url_for_ssrf resolves the attacker-controlled X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url header host once at middleware time, but the outbound request is built with the raw hostname and resolves it again at connection time with no IP pinning. An attacker-controlled DNS-rebinding name can return a public IP during validation and 169.254.169.254 or anothe 6.5 Sep 14, 2026 MEDIUM GHSA-489g-7rxv-6c8q mcp-atlassian: DNS-rebind bypass revives header SSRF 6.5 Jul 10, 2026 HIGH GHSA-wm45-qh3g-v83f mcp-atlassian: path traversal leaks server files+creds 7.7 Jul 10, 2026 HIGH GHSA-g5r6-gv6m-f5jv mcp-atlassian: path traversal leaks secrets via injection 7.7 Jul 10, 2026 HIGH CVE-2026-27826 mcp-atlassian: SSRF allows internal network access 8.2 Mar 10, 2026 CRITICAL CVE-2026-27825 mcp-atlassian: Path Traversal enables file access 9.1 Mar 10, 2026

Showing 26–36 of 36

Frequently asked questions

What is MCP Atlassian?

MCP Atlassian is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does MCP Atlassian have?

MCP Atlassian has 39 known CVEs, 3 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is MCP Atlassian distributed in?

MCP Atlassian is distributed via the pip ecosystem and categorized as ai agents.

Where does the MCP Atlassian vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of MCP Atlassian?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor MCP Atlassian in your stack

Get instant alerts when new vulnerabilities affect MCP Atlassian. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring