CVE-2026-77260 | sooperset mcp-atlassian up to 0.21.99 File Upload upload_attachment file_path path traversal

SecurityVulns

A vulnerability categorized as critical has been discovered in sooperset mcp-atlassian up to 0.21.99. The affected element is the function upload_attachment of the component File Upload. The manipulation of the argument file_path results in path traversal.

This vulnerability is reported as CVE-2026-77260. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More