{"id":"CVE-2026-77250","title":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)","summary":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian direc…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-312"],"vendor":"sooperset","product":"mcp-atlassian","affected":["mcp-atlassian < 0.22.0"],"patched":["mcp-atlassian 0.22.0"],"published":"2026-09-22","updated":"2026-09-23","sourceUpdated":"2026-09-23T18:28:25.093","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77250","references":[{"url":"https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/pull/1448","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-g5xv-mhgm-v5f6","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-g5xv-mhgm-v5f6","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77250"},{"url":"https://github.com/advisories/GHSA-g5xv-mhgm-v5f6"},{"url":"https://github.com/sooperset/mcp-atlassian"}],"tags":["nvd","cve.org","exploit-available","ghsa","pip","osv"],"epss":0.00105,"epssPercentile":0.01191,"aliases":["GHSA-g5xv-mhgm-v5f6"],"ecosystem":"pip","exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-22T18:42:32.636268Z"},"ingestedAt":"2026-09-22T18:08:12.470Z","slug":"CVE-2026-77250","body":"## Overview\n\nMCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian directory using process-default permissions. On systems with a permissive umask, same-group or other local users and processes can read the persisted tokens and reuse the associated Atlassian access. The advisory traces the vulnerable input and processing flow through OAuthConfig._save_tokens, ~/.mcp-atlassian/oauth-<client_id>.json, access_token, and refresh_token, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-77250)\n\nAffected packages:\n\n- `mcp-atlassian < 0.22.0`\n\nPatched in:\n\n- `mcp-atlassian 0.22.0`\n\nSource: https://github.com/advisories/GHSA-g5xv-mhgm-v5f6","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":209320,"id":"CVE-2026-77250","ts":1790104202756,"field":"exploit_available","old":"false","new":"true"}]}