CVE-2026-77257 | sooperset Mcp Atlassian up to 0.21.x Upload upload_attachment file_path path traversal

SecurityVulns

A vulnerability described as critical has been identified in sooperset Mcp Atlassian up to 0.21.x. Affected is the function upload_attachment of the component Upload. Executing a manipulation of the argument file_path can lead to path traversal.

This vulnerability is handled as CVE-2026-77257. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More