MCP Vulnerability in Atlassian Products Allows Unrestricted File Writes
CVE-2026-77271
8.3HIGH
What is CVE-2026-77271?
The MCP Atlassian server enables attackers to manipulate the system by exploiting an issue in path validation. With default settings, the validate_safe_path function uses the current working directory, which can lead to unauthorized file writes in Confluence and Jira. When base_dir is omitted in attachment calls, an attacker could potentially overwrite Python modules, facilitating code execution upon later imports. This vulnerability has been addressed in version 0.22.0, emphasizing the need for users to upgrade to mitigate risks.
Affected Version(s)
mcp-atlassian < 0.22.0
