CVE-2026-77258 | sooperset mcp-atlassian up to 0.21.x Attachments attachments.py upload_attachment file_path path traversal

SecurityVulns

A vulnerability, which was classified as problematic, was found in sooperset mcp-atlassian up to 0.21.x. Affected by this vulnerability is the function upload_attachment of the file src/mcp_atlassian/confluence/attachments.py of the component Attachments. The manipulation of the argument file_path results in path traversal.

This vulnerability is identified as CVE-2026-77258. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More