Vibe Coding
NVD publishes 28 MCP Atlassian CVEs in one day, including a 10.0 unauthenticated credential fallback
On 2026-09-22 NVD published 28 CVEs against sooperset/mcp-atlassian, all fixed in 0.22.0. The worst, CVE-2026-77244 (CVSS 10.0), lets the HTTP transport accept requests with no verified user identity and fall back to the operator's global Jira/Confluence credentials. Others cover upload_attachment reading arbitrary server files, DNS-rebinding SSRF, ENABLED_TOOLS not re-checked at tools/call time, and plaintext OAuth token files. 0.22.0 shipped in July and the current release is 0.23.1, so the bugs are not new. Today's news is that the disclosure is public, and any shared HTTP deployment still pinned below 0.22.0 is exposed.
Source
↳ Follow the thread