PYSEC-2026-4084
Vulnerability from pysec - Published: 2026-10-01 16:38 - Updated: 2026-10-01 17:10Summary
The UserTokenMiddleware extracts URLs from X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url HTTP headers and passes them directly to API client constructors without any SSRF validation.
Affected Package
- Ecosystem: PyPI
- Package: mcp-atlassian
- Affected versions: all versions before fix commit 5cd697dfce91
- Patched versions: >= commit 5cd697dfce91
Details
In main.py, _process_authentication_headers() extracts URLs from ASGI headers without validation. In dependencies.py, get_jira_fetcher() creates JiraConfig with url=jira_url_header directly. There is no validate_url call, no IP range check, no hostname validation.
The fix adds URL validation to some paths but the header-based URL extraction in _process_authentication_headers() still passes raw URLs through. The derived config objects use the header URL directly and the fetcher makes HTTP requests to that URL.
PoC
jira_url_header = headers.get(b"x-atlassian-jira-url")
jira_url_str = jira_url_header.decode("latin-1") if jira_url_header else None
service_headers["X-Atlassian-Jira-Url"] = jira_url_str
Steps to reproduce:
1. git clone https://github.com/sooperset/mcp-atlassian /tmp/mcp-atlassian_test
2. cd /tmp/mcp-atlassian_test && git checkout 5cd697dfce91~1
3. pip install -e .
4. python3 poc.py
Expected output:
VULNERABILITY CONFIRMED
User-supplied URLs from HTTP headers passed directly to JiraConfig/JiraFetcher with no SSRF validation
Impact
An attacker can set X-Atlassian-Jira-Url: http://169.254.169.254/latest/meta-data/ to access AWS instance metadata, or target any internal service. The server makes authenticated HTTP requests to the attacker-specified URL.
Suggested Remediation
Validate all user-supplied URLs against an allowlist of permitted hostnames or reject private/loopback/link-local IP ranges. Consider requiring server-side configuration of allowed Atlassian instance URLs.
| Name | purl | mcp-atlassian | pkg:pypi/mcp-atlassian |
|---|
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "mcp-atlassian",
"purl": "pkg:pypi/mcp-atlassian"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.22.0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.1.1",
"0.1.10",
"0.1.11",
"0.1.12",
"0.1.13",
"0.1.14",
"0.1.15",
"0.1.16",
"0.1.2",
"0.1.3",
"0.1.4",
"0.1.6",
"0.1.7",
"0.1.8",
"0.1.9",
"0.10.0",
"0.10.1",
"0.10.2",
"0.10.3",
"0.10.4",
"0.10.5",
"0.10.6",
"0.11.0",
"0.11.1",
"0.11.10",
"0.11.11",
"0.11.12",
"0.11.2",
"0.11.2a2",
"0.11.3",
"0.11.4",
"0.11.5",
"0.11.6",
"0.11.7",
"0.11.8",
"0.11.9",
"0.12.0",
"0.13.0",
"0.13.1",
"0.14.0",
"0.14.1",
"0.14.2",
"0.14.3",
"0.15.0",
"0.16.0",
"0.16.1",
"0.17.0",
"0.18.0",
"0.18.1",
"0.19.0",
"0.2.0",
"0.2.1",
"0.2.2",
"0.2.3",
"0.2.4",
"0.2.5",
"0.2.6",
"0.20.0",
"0.20.1",
"0.21.0",
"0.21.1",
"0.3.0",
"0.3.1",
"0.4.0",
"0.5.0",
"0.6.0",
"0.6.1",
"0.6.2",
"0.6.3",
"0.6.4",
"0.6.5",
"0.7.0",
"0.7.1",
"0.8.0",
"0.8.1",
"0.8.2",
"0.8.3",
"0.8.4",
"0.9.0"
]
}
],
"aliases": [
"CVE-2026-77267",
"GHSA-5wf4-jqxh-8gm3"
],
"details": "### Summary\n\nThe `UserTokenMiddleware` extracts URLs from `X-Atlassian-Jira-Url` and `X-Atlassian-Confluence-Url` HTTP headers and passes them directly to API client constructors without any SSRF validation.\n\n### Affected Package\n\n- **Ecosystem:** PyPI\n- **Package:** mcp-atlassian\n- **Affected versions:** all versions before fix commit 5cd697dfce91\n- **Patched versions:** \u003e= commit 5cd697dfce91\n\n### Details\n\nIn `main.py`, `_process_authentication_headers()` extracts URLs from ASGI headers without validation. In `dependencies.py`, `get_jira_fetcher()` creates `JiraConfig` with `url=jira_url_header` directly. There is no `validate_url` call, no IP range check, no hostname validation.\n\nThe fix adds URL validation to some paths but the header-based URL extraction in `_process_authentication_headers()` still passes raw URLs through. The derived config objects use the header URL directly and the fetcher makes HTTP requests to that URL.\n\n### PoC\n\n```python\njira_url_header = headers.get(b\"x-atlassian-jira-url\")\njira_url_str = jira_url_header.decode(\"latin-1\") if jira_url_header else None\nservice_headers[\"X-Atlassian-Jira-Url\"] = jira_url_str\n```\n\n**Steps to reproduce:**\n1. `git clone https://github.com/sooperset/mcp-atlassian /tmp/mcp-atlassian_test`\n2. `cd /tmp/mcp-atlassian_test \u0026\u0026 git checkout 5cd697dfce91~1`\n3. `pip install -e .`\n4. `python3 poc.py`\n\n**Expected output:**\n```\nVULNERABILITY CONFIRMED\nUser-supplied URLs from HTTP headers passed directly to JiraConfig/JiraFetcher with no SSRF validation\n```\n\n### Impact\n\nAn attacker can set `X-Atlassian-Jira-Url: http://169.254.169.254/latest/meta-data/` to access AWS instance metadata, or target any internal service. The server makes authenticated HTTP requests to the attacker-specified URL.\n\n### Suggested Remediation\n\nValidate all user-supplied URLs against an allowlist of permitted hostnames or reject private/loopback/link-local IP ranges. Consider requiring server-side configuration of allowed Atlassian instance URLs.",
"id": "PYSEC-2026-4084",
"modified": "2026-10-01T17:10:30.108379Z",
"published": "2026-10-01T16:38:36.058700Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-5wf4-jqxh-8gm3"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77267"
},
{
"type": "WEB",
"url": "https://github.com/sooperset/mcp-atlassian/pull/1448"
},
{
"type": "WEB",
"url": "https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460"
},
{
"type": "PACKAGE",
"url": "https://github.com/sooperset/mcp-atlassian"
},
{
"type": "WEB",
"url": "https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0"
},
{
"type": "PACKAGE",
"url": "https://pypi.org/project/mcp-atlassian"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-5wf4-jqxh-8gm3"
}
],
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "mcp-atlassian has an incomplete SSRF remediation"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.