
Atlassian MCP had a clean path-traversal (CVE-2026-73498). confluence_upload_attachment took a client-supplied file path and passed it straight to open() with no validation. Authenticated MCP client → arbitrary file read of anything the server process can reach (credentials and env vars called out in the advisory). Fixed in v0.22.0. Classic “tool parameter treated as trusted” failure mode. https://adversa.ai/blog/top-mcp-security-resources-september-2026/ #MCP #AppSec #Cybersecurity #AI #Claude #VulnerabilityResearch #Infosec
Post summary
The post reports a path‑traversal flaw (CVE‑2026‑73498) in Atlassian MCP that lets authenticated clients read arbitrary files and notes it has been patched in v0.22.0.

