{"id":"CVE-2026-77249","title":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)","summary":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin._lookup_user_by_permissions uses the module-level requests.get function instead of the fetcher's protecte…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-918"],"vendor":"mcp-atlassian","product":"mcp-atlassian","affected":["mcp-atlassian < 0.22.0"],"patched":["mcp-atlassian 0.22.0"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:17:07.850","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77249","references":[{"url":"https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/pull/1448","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-v9m3-wfh8-5646","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-v9m3-wfh8-5646"}],"tags":["nvd","ghsa","pip","cve.org"],"aliases":["GHSA-v9m3-wfh8-5646"],"ecosystem":"pip","ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-22T19:35:45.757999Z"},"ingestedAt":"2026-09-22T19:09:10.004Z","slug":"CVE-2026-77249","body":"## Overview\n\nMCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin._lookup_user_by_permissions uses the module-level requests.get function instead of the fetcher's protected session. A caller-controlled public Jira URL can redirect that unhooked request to an internal address, bypassing the redirect checks added for CVE-2026-27826. The advisory traces the vulnerable input and processing flow through JiraUserMixin._lookup_user_by_permissions, requests.get, self.jira._session.get, and _make_ssrf_safe_hook, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-77249)\n\nAffected packages:\n\n- `mcp-atlassian < 0.22.0`\n\nPatched in:\n\n- `mcp-atlassian 0.22.0`\n\nSource: https://github.com/advisories/GHSA-v9m3-wfh8-5646","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}