
If an agent can call Confluence MCP, it can also walk your disk. CVE-2026-77258: upload_attachment accepted any caller path and attached the file. No workspace boundary. Fixed in mcp-atlassian 0.22.0. Check which boxes still run older builds.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data readable by the server process. This issue is fixed in version 0.22.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

If an agent can call Confluence MCP, it can also walk your disk. CVE-2026-77258: upload_attachment accepted any caller path and attached the file. No workspace boundary. Fixed in mcp-atlassian 0.22.0. Check which boxes still run older builds.