pypi

mcp-atlassian

View on pypi registry
33 Total advisories
33 Vulnerabilities
0 Malware

Dependency scanning

Check whether mcp-atlassian is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 10.0
PyPI

CVE-2026-77244

[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token

UNKNOWN
PyPI

CVE-2026-77251

MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)

UNKNOWN
PyPI

CVE-2026-77257

MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths

MEDIUM 5.3
PyPI

CVE-2026-77249

MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup

HIGH 8.6
PyPI

CVE-2026-77262

MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)

MEDIUM 6.5
PyPI

CVE-2026-77266

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call

HIGH 7.4
PyPI

CVE-2026-77246

MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path

HIGH 7.1
PyPI

CVE-2026-77253

MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files

UNKNOWN
PyPI

CVE-2026-77274

MCP Atlassian: SSRF Protection Bypass

MEDIUM 6.1
PyPI

CVE-2026-77250

MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions

UNKNOWN
PyPI

CVE-2026-77267

mcp-atlassian has an incomplete SSRF remediation

MEDIUM 6.5
PyPI

CVE-2026-77270

MCP Atlassian: Arbitrary File Read via Upload Attachment Tools

MEDIUM 5.4
PyPI

CVE-2026-77272

MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler

HIGH 8.8
PyPI

CVE-2026-77243

MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass

HIGH 7.7
PyPI

CVE-2026-77258

MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()

UNKNOWN
PyPI

CVE-2026-77260

MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)

MEDIUM 5.9
PyPI

CVE-2026-77265

MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow

MEDIUM 5.5
PyPI

CVE-2026-77268

MCP Atlassian: Insecure File Permissions on OAuth Token Storage

HIGH 8.6
PyPI

CVE-2026-77255

MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue

HIGH 7.7
PyPI

CVE-2026-77259

MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials

MEDIUM 6.5
PyPI

CVE-2026-77269

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)

HIGH 8.6
PyPI

CVE-2026-77248

MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport

HIGH 7.1
PyPI

CVE-2026-77261

MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches

UNKNOWN
PyPI

CVE-2026-77247

MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters

UNKNOWN
PyPI

CVE-2026-77271

MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)

HIGH 7.7
PyPI

CVE-2026-73496

mcp-atlassian: Arbitrary server-side file read via attachment upload

MEDIUM 6.5
PyPI

CVE-2026-73497

MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)

HIGH 7.7
PyPI

CVE-2026-73498

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

HIGH 7.7
PyPI

CVE-2026-73498

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

HIGH 8.2
PyPI

CVE-2026-27826

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

HIGH 8.2
PyPI

CVE-2026-27826

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

CRITICAL 9.0
PyPI

CVE-2026-27825

MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment

CRITICAL 9.0
PyPI

CVE-2026-27825

MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes