Dependency scanning
Check whether mcp-atlassian is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-77244
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
CVE-2026-77251
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
CVE-2026-77257
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
CVE-2026-77249
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
CVE-2026-77262
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
CVE-2026-77266
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
CVE-2026-77246
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
CVE-2026-77253
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
CVE-2026-77274
MCP Atlassian: SSRF Protection Bypass
CVE-2026-77250
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
CVE-2026-77267
mcp-atlassian has an incomplete SSRF remediation
CVE-2026-77270
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
CVE-2026-77272
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
CVE-2026-77243
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
CVE-2026-77258
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
CVE-2026-77260
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
CVE-2026-77265
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
CVE-2026-77268
MCP Atlassian: Insecure File Permissions on OAuth Token Storage
CVE-2026-77255
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
CVE-2026-77259
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
CVE-2026-77269
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)
CVE-2026-77248
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
CVE-2026-77261
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
CVE-2026-77247
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
CVE-2026-77271
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
CVE-2026-73496
mcp-atlassian: Arbitrary server-side file read via attachment upload
CVE-2026-73497
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
CVE-2026-73498
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
CVE-2026-73498
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
CVE-2026-27826
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
CVE-2026-27826
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
CVE-2026-27825
MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
CVE-2026-27825
MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes