
MCP Atlassian に SSRF の脆弱性(CVE-2026-77261)。AI エージェントから Jira / Confluence をつなぐ MCP サーバーです。修正版 0.22.0 は GitHub のアドバイザリで確認しました。使っている方は更新を。 https://ai-news.autoarticles.net/article/post_1790478062279_mr5mpe
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, _make_ssrf_safe_hook is omitted from JiraFetcher and ConfluenceFetcher sessions created through the basic-auth and oauth_pat branches. If an attacker-controlled or compromised configured Atlassian instance returns a redirect to an internal address, those sessions can follow the redirect without revalidating its destination. This issue is fixed in version 0.22.0.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

MCP Atlassian に SSRF の脆弱性(CVE-2026-77261)。AI エージェントから Jira / Confluence をつなぐ MCP サーバーです。修正版 0.22.0 は GitHub のアドバイザリで確認しました。使っている方は更新を。 https://ai-news.autoarticles.net/article/post_1790478062279_mr5mpe
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | mcp-atlassian | mcp_atlassian | - | - | - |