CVE-2026-73498 | sooperset mcp-atlassian up to 0.21.x Attachments attachments.py _upload_attachment_direct file_path path traversal
A vulnerability identified as problematic has been detected in sooperset mcp-atlassian up to 0.21.x. This vulnerability affects the function _upload_attachment_direct of the file src/mcp_atlassian/confluence/attachments.py of the component Attachments. This manipulation of the argument file_path causes path traversal.
This vulnerability appears as CVE-2026-73498. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More