CVE-2026-77272: MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler.sendresponse in oauthsetup.py and interpolated into an HTML page without escaping. A crafted authorization callback can inject markup or script that executes in the browser of a user completing the OAuth flow. This issue is fixed in version 0.22.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MCP Atlassianto a version that resolves this vulnerability.Fixed in 0.22.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of MCP Atlassian versions earlier than 0.22.0 are exposed when they are completing the OAuth flow and their browser processes a crafted authorization callback.
What does an attacker need to exploit it?
An attacker needs to cause a user completing OAuth to receive a crafted authorization callback containing a malicious OAuth error query parameter. No prior privileges are required, but user interaction is required.
What version fixes the vulnerability?
Upgrade MCP Atlassian to version 0.22.0 or later. The vulnerable behavior affects versions before 0.22.0.