Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-93xw-j965-9mx3
  • PyPI/mcp-atlassian
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path() yesterday
  • Fix available
  • Severity - 7.7 (High)
GHSA-g5xv-mhgm-v5f6
  • PyPI/mcp-atlassian
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions yesterday
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-v9m3-wfh8-5646
  • PyPI/mcp-atlassian
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-f6pj-qv47-g96w
  • PyPI/mcp-atlassian
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters yesterday
  • Fix available
GHSA-wrhw-j3f9-8vc6
  • PyPI/mcp-atlassian
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token yesterday
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-hgcf-4mq8-5266
  • PyPI/mcp-atlassian
MCP Atlassian: SSRF Protection Bypass yesterday
  • Fix available
  • Severity - 8.8 (High)
GHSA-6vmq-24h2-pj7j
  • PyPI/mcp-atlassian
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4) yesterday
  • Fix available
  • Severity - 8.3 (High)
GHSA-5wf4-jqxh-8gm3
  • PyPI/mcp-atlassian
mcp-atlassian has an incomplete SSRF remediation yesterday
  • Fix available
  • Severity - 8.3 (High)
GHSA-g2r2-3j32-j27x
  • PyPI/mcp-atlassian
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler yesterday
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-p6hp-93wp-fh6p
  • PyPI/mcp-atlassian
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4) yesterday
  • Fix available
  • Severity - 8.6 (High)
GHSA-4596-2p6p-28cv
  • PyPI/mcp-atlassian
MCP Atlassian: Insecure File Permissions on OAuth Token Storage yesterday
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-6cr4-ccf3-x7h4
  • PyPI/mcp-atlassian
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials yesterday
  • Fix available
  • Severity - 7.7 (High)
GHSA-6529-c226-h328
  • PyPI/mcp-atlassian
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-f26r-j276-ggg4
  • PyPI/mcp-atlassian
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools yesterday
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-49xv-9743-pw8w
  • PyPI/mcp-atlassian
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow yesterday
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-mfv2-4wvm-9pgp
  • PyPI/mcp-atlassian
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call yesterday
  • Fix available
  • Severity - 6.5 (Medium)