{"id":"CVE-2026-77272","title":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)","summary":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oauth_setup.py and interpolated into an …","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"sooperset","product":"mcp-atlassian","affected":["mcp-atlassian < 0.22.0"],"patched":["mcp-atlassian 0.22.0"],"published":"2026-09-22","updated":"2026-09-23","sourceUpdated":"2026-09-23T18:12:04.247","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77272","references":[{"url":"https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/pull/1448","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0","label":"security-advisories@github.com"},{"url":"https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-g2r2-3j32-j27x","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-g2r2-3j32-j27x"}],"tags":["nvd","cve.org","ghsa","pip"],"epss":0.00338,"epssPercentile":0.27339,"aliases":["GHSA-g2r2-3j32-j27x"],"ecosystem":"pip","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-23T14:10:19.747917Z"},"ingestedAt":"2026-09-22T19:09:10.008Z","slug":"CVE-2026-77272","body":"## Overview\n\nMCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oauth_setup.py and interpolated into an HTML page without escaping. A crafted authorization callback can inject markup or script that executes in the browser of a user completing the OAuth flow. This issue is fixed in version 0.22.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-77272)\n\nAffected packages:\n\n- `mcp-atlassian < 0.22.0`\n\nPatched in:\n\n- `mcp-atlassian 0.22.0`\n\nSource: https://github.com/advisories/GHSA-g2r2-3j32-j27x","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}