CVE-2026-77270 | sooperset mcp-atlassian up to 0.21.x Attachment Upload file_path path traversal

SecurityVulns

A vulnerability marked as problematic has been reported in sooperset mcp-atlassian up to 0.21.x. This vulnerability affects the function confluence_upload_attachment/jira_upload_attachment of the component Attachment Upload. The manipulation of the argument file_path leads to path traversal.

This vulnerability is uniquely identified as CVE-2026-77270. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More