
Upwind Security MDR@UpwindMDR
🚨 HIGH - Dual Vulnerabilities in MCP Atlassian (CVE-2026-73496 & CVE-2026-73497) MCP Atlassian patched two flaws allowing local file disclosure and SSRF attacks: • CVE-2026-73496: Path traversal in attachment uploads allows attackers to read arbitrary server files and secrets. • CVE-2026-73497: TOCTOU DNS-rebinding SSRF flaw enables access to internal endpoints and cloud metadata. 👉 Affected: mcp-atlassian prior to 0.22.0 | Upgrade to version 0.22.0 or later immediately
0000050
303 followersView on X
