CVE-2026-27825
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `download_path` parameter that is written to without any directory boundary enforcement. An attacker who can call this tool and supply or access a Confluence attachment with malicious content can write arbitrary content to any path the server process has write access to. Because the attacker controls both the write destination and the written content (via an uploaded Confluence attachment), this constitutes for arbitrary code execution (for example, writing a valid cron entry to `/etc/cron.d/` achieves code execution within one scheduler cycle with no server restart required). Version 0.17.0 fixes the issue.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 12.71%
- CWE
- CWE-22, CWE-73
- Published
- 2026-03-10
- Last modified
- 2026-03-16
Affected products
- sooperset mcp-atlassian
Weakness type
Related vulnerabilities
- CVE-2026-86087 — IBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the system
- CVE-2026-76652 — Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600
- CVE-2026-88046 — rclone: source object names can escape the configured root on upload
- CVE-2026-88014 — rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
- CVE-2026-88940 — knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
- CVE-2026-88938 — knowns through 0.33.0 Path Traversal via code.find MCP tool
- CVE-2026-88937 — knowns through 0.33.0 Path Traversal via Template Engine
- CVE-2026-81789 — WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary File Deletion vulnerability