GHSA-cc5h-2pwp-pvcc

Suggest an improvement
Source
https://github.com/advisories/GHSA-cc5h-2pwp-pvcc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-cc5h-2pwp-pvcc/GHSA-cc5h-2pwp-pvcc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cc5h-2pwp-pvcc
Aliases
Published
2026-09-22T20:34:43Z
Modified
2026-09-22T21:00:04Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
Details

Summary

In the documented multi-user HTTP deployment (--transport streamable-http with global operator Atlassian credentials), sooperset/mcp-atlassian exposes all tools to unauthenticated network clients, and the upload_attachment tool reads an attacker-supplied file_path with no path validation. Chained, an unauthenticated network attacker reads arbitrary files on the MCP server host (e.g. /proc/self/environ → the operator's Atlassian API token + .env secrets, ~/.ssh/id_rsa, /etc/passwd) by uploading them to an attacker-chosen page/issue and reading them back.

Details

Missing authentication (transport):

  • streamable-http binds 0.0.0.0 by default (src/mcp_atlassian/__init__.py:151).
  • The OAuth-proxy auth provider is opt-in (ATLASSIAN_OAUTH_PROXY_ENABLE, default false), so main_mcp is built with auth=None (src/mcp_atlassian/servers/main.py:724-731, 813-817).
  • UserTokenMiddleware._parse_auth_header sets auth_validation_error only for a malformed Authorization header; a request with no Authorization header passes through (main.py:416-446, 582-595).
  • _get_fetcher then falls through to the global credential fallback using the operator's .env Atlassian token (src/mcp_atlassian/servers/dependencies.py:644-676). check_write_access gates only on read-only mode, not auth → read and write tools reachable.

Arbitrary file read (sink):

  • upload_attachment's file_path flows unsanitized into open(file_path, 'rb') — Confluence src/mcp_atlassian/confluence/attachments.py:477 (from servers/confluence.py:1294-1369); Jira src/mcp_atlassian/jira/attachments.py:386 (from servers/jira.py:1609-1673). No validate_safe_path / allowlist (contrast the download flow, hardened after CVE-2026-27825).

Proof of Concept

# unauthenticated (no Authorization header) against a default streamable-http deployment:
tools/call upload_attachment { "file_path": "/proc/self/environ", "page_id": "<attacker-chosen>" }
# then read it back:
tools/call download_attachment { ... }   # returns the bytes (base64) -> operator's ATLASSIAN token + .env secrets

Impact

Unauthenticated arbitrary local file read on the MCP server host — including the operator's Atlassian API token and .env secrets — a boundary the Atlassian-scoped tool must not cross, plus unauthenticated use of every read/write Atlassian tool as the operator's (often admin) principal. Distinct from GHSA-xjgw-4wvw-rgm4 (file write via download_path) and GHSA-7r34-79r5-rcc9 (URL-header SSRF).

Suggested fix

Require authentication on the streamable-http transport by default (do not fall back to operator global credentials for unauthenticated requests); apply validate_safe_path/allowlist to file_path in upload_attachment as the download flow already does.

Affected

mcp-atlassian <= 0.21.1.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-22T20:34:43Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

PyPI / mcp-atlassian

Package

Name
mcp-atlassian
View open source insights on deps.dev
Purl
pkg:pypi/mcp-atlassian

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.22.0

Affected versions

0.*
0.1.1
0.1.2
0.1.3
0.1.4
0.1.6
0.1.7
0.1.8
0.1.9
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.1
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.10.0
0.10.1
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.11.0
0.11.1
0.11.2a2
0.11.2
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.11.10
0.11.11
0.11.12
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.16.0
0.16.1
0.17.0
0.18.0
0.18.1
0.19.0
0.20.0
0.20.1
0.21.0
0.21.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-cc5h-2pwp-pvcc/GHSA-cc5h-2pwp-pvcc.json"