In the documented multi-user HTTP deployment (--transport streamable-http with global operator Atlassian credentials), sooperset/mcp-atlassian exposes all tools to unauthenticated network clients, and the upload_attachment tool reads an attacker-supplied file_path with no path validation. Chained, an unauthenticated network attacker reads arbitrary files on the MCP server host (e.g. /proc/self/environ → the operator's Atlassian API token + .env secrets, ~/.ssh/id_rsa, /etc/passwd) by uploading them to an attacker-chosen page/issue and reading them back.
Missing authentication (transport):
0.0.0.0 by default (src/mcp_atlassian/__init__.py:151).ATLASSIAN_OAUTH_PROXY_ENABLE, default false), so main_mcp is built with auth=None (src/mcp_atlassian/servers/main.py:724-731, 813-817).UserTokenMiddleware._parse_auth_header sets auth_validation_error only for a malformed Authorization header; a request with no Authorization header passes through (main.py:416-446, 582-595)._get_fetcher then falls through to the global credential fallback using the operator's .env Atlassian token (src/mcp_atlassian/servers/dependencies.py:644-676). check_write_access gates only on read-only mode, not auth → read and write tools reachable.Arbitrary file read (sink):
upload_attachment's file_path flows unsanitized into open(file_path, 'rb') — Confluence src/mcp_atlassian/confluence/attachments.py:477 (from servers/confluence.py:1294-1369); Jira src/mcp_atlassian/jira/attachments.py:386 (from servers/jira.py:1609-1673). No validate_safe_path / allowlist (contrast the download flow, hardened after CVE-2026-27825).# unauthenticated (no Authorization header) against a default streamable-http deployment:
tools/call upload_attachment { "file_path": "/proc/self/environ", "page_id": "<attacker-chosen>" }
# then read it back:
tools/call download_attachment { ... } # returns the bytes (base64) -> operator's ATLASSIAN token + .env secrets
Unauthenticated arbitrary local file read on the MCP server host — including the operator's Atlassian API token and .env secrets — a boundary the Atlassian-scoped tool must not cross, plus unauthenticated use of every read/write Atlassian tool as the operator's (often admin) principal. Distinct from GHSA-xjgw-4wvw-rgm4 (file write via download_path) and GHSA-7r34-79r5-rcc9 (URL-header SSRF).
Require authentication on the streamable-http transport by default (do not fall back to operator global credentials for unauthenticated requests); apply validate_safe_path/allowlist to file_path in upload_attachment as the download flow already does.
mcp-atlassian <= 0.21.1.
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-22T20:34:43Z",
"nvd_published_at": null,
"severity": "HIGH"
}