How a prompt injection in a Jira ticket led to discovering a critical vulnerability in an MCP server
While testing AI agent integrations using RunPod's OpenWebUI connected to MCP (Model Context Protocol) servers, I discovered that mcp-atlassian failed to sanitize file paths in its upload_file tool. An attacker who can influence content processed by an AI agent (via Jira tickets, Confluence pages, or other Atlassian content) can inject prompts that cause the agent to read arbitrary files from the server.
Impact: Attackers can exfiltrate sensitive files including /etc/passwd, SSH keys, environment variables, and application secrets from any server running mcp-atlassian with an AI agent.
Live demonstration of the vulnerability using RunPod OpenWebUI + MCP
I was testing AI agent workflows using:
The mcp-atlassian server's upload_file tool accepted a file_path parameter without sanitization:
HIGH - Arbitrary file read exposes secrets, credentials, and sensitive data
NETWORK - Exploitable remotely via malicious Jira/Confluence content
LOW - Only needs ability to create Jira tickets or Confluence pages
REQUIRED - AI agent must process the malicious content