mcp-atlassian Package SSRF Vulnerability Under Investigation
The mcp-atlassian package appears to have an incomplete fix for a SSRF vulnerability, potentially allowing unauthenticated SSRF to cloud metadata and internal services. Users of mcp-atlassian (pypi) version 0.17.0 and above should assess their exposure.
What happened
An early warning has been issued regarding a potential SSRF vulnerability in the mcp-atlassian package. The vulnerability reportedly stems from an incomplete fix that allows a TOCTOU attack via DNS-rebinding, enabling unauthenticated SSRF to cloud metadata and internal services. The fix resolves the host once at middleware time but fails to pin the validated IP, leading to re-resolution at connect time.
The affected component is mcp-atlassian (pypi) version 0.17.0 and above. The issue is under investigation, and it is recommended to monitor for patches that address the incomplete SSRF mitigation. Primary sources should be consulted for the most up-to-date information and detailed technical insights.
Professional software engineers using mcp-atlassian should assess their exposure to this potential vulnerability. It is advisable to stay informed through official advisories and consider implementing additional security measures until a confirmed patch is available.
How 0Day mitigates this
mcp-atlassian is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.