VYPR

apk package

chainguard/mcp-atlassian

pkg:apk/chainguard/mcp-atlassian

Vulnerabilities (5)

  • CVE-2026-73498HigAug 12, 2026
    affected < 0.22.1-r0fixed 0.22.1-r0

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluence/attachments.py through _upload

  • CVE-2026-69247HigAug 3, 2026
    affected < 0.23.0-r1fixed 0.23.0-r1

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguish

  • CVE-2026-27124MedApr 3, 2026
    affected < 0.23.0-r0fixed 0.23.0-r0

    FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMCP MCP server via a FastMCP OAuthProxy using GitHub OAuth, it was discovered that the FastMCP OAuthPr

  • CVE-2025-64340MedApr 3, 2026
    affected < 0.23.0-r0fixed 0.23.0-r0

    FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed to fastmcp install claude-code or fastmcp install gemini-cli. These install paths use

  • CVE-2026-32871CriApr 2, 2026
    affected < 0.23.0-r0fixed 0.23.0-r0

    FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend servic