system: OPERATIONAL
← back to all hacks
SUPPLY CHAIN MEDIUM NEW

Two MCP servers, one pattern: tools that read files and leak secrets

Summer 2026 advisories for the Atlassian and ArcadeDB MCP servers show tool handlers skipping checks that sibling code paths already had. Both are patched; here is how to audit yours.

2026-10-03 // 6 min affects: mcp-atlassian, arcadedb, mcp-servers, agent-tool-layers

What is this?

In July 2026, maintainers published advisories for two unrelated Model Context Protocol (MCP) servers. The community Atlassian server (sooperset/mcp-atlassian) had an arbitrary file-read flaw in its Confluence attachment-upload tool, advisory dated July 10, 2026, fixed in version 0.22.0. The ArcadeDB database exposed its high-availability cluster token through an MCP settings tool, advisory dated July 17, 2026, fixed in 26.7.3. NVD entries followed in August, and Adversa’s September 2026 MCP roundup listed both.

Neither is a novel attack class. They matter because the root cause is the same in both: a protection existed elsewhere in the codebase and the new tool handler did not use it. See also the broader pattern of MCP backend vulnerabilities.

How it works

In the Atlassian server, the upload tool passed a client-supplied file path straight to a file open call. The advisory notes that a path-validation helper already protected the download functions; the upload function simply did not call it. An authenticated client, or an agent steered by a prompt injection, could therefore name a local file such as an environment file and have the server attach it to a Confluence page, moving server-side credentials to a location the caller can read.

In ArcadeDB, the MCP get_server_settings tool returned configuration values without masking the cluster token. The advisory says the fix applies the same “hidden setting” check that an earlier fix had added to the regular server-info handler. Per the advisory, a non-root user with MCP access could read the token and impersonate a root user.

The shared lesson: an MCP tool is a new entry point to the same backend. Each tool must re-apply authorization, path validation, and output masking, because the model, or whoever manipulates it, chooses the arguments.

Why it matters

MCP servers typically run with the credentials of the service they wrap. A file-read primitive there exposes tokens that unlock the wider environment, and a settings tool that echoes secrets turns any low-privilege agent session into an administrator. Both advisories describe low-privilege access sufficing, and the Atlassian advisory explicitly mentions prompt injection as a trigger path, so exposure is not limited to hostile users.

Both are fixed, and no in-the-wild exploitation is documented in the sources reviewed.

Defenses

  • Upgrade. Move to mcp-atlassian 0.22.0 or later and ArcadeDB 26.7.3 or later. The Atlassian advisory lists no workaround.
  • Rotate secrets. If either server was exposed to untrusted users or injected content, rotate the Confluence API token and the ArcadeDB cluster token.
  • Audit sibling code paths. When a fix lands in one handler, search for every other handler touching the same resource (upload vs download, settings vs server info) and confirm each applies the same check.
  • Constrain file arguments. Resolve paths against an allow-listed base directory, reject traversal and absolute paths, and never expose arbitrary local paths as tool parameters when content can be passed directly.
  • Mask by default. Treat configuration output as secret unless marked safe, and test tools for leakage of tokens and keys.
  • Least privilege. Run MCP servers as a dedicated low-privilege user with minimal filesystem and network reach, and do not mount credential files they do not need.
  • Gate agent calls. Require human approval for tools that read local files or return configuration, and log tool arguments for review.

Status

ItemDetail
mcp-atlassianAffected: before 0.22.0. Fixed: 0.22.0. Advisory 2026-07-10. CVE-2026-73498, CVSS 7.7 (v3.1)
ArcadeDBAffected: 26.7.2 and earlier. Fixed: 26.7.3. Advisory 2026-07-17. CVE-2026-67357, CVSS 7.5 (v3.1)
WorkaroundsNone documented in either advisory
Exploitation in the wildNot reported in the reviewed sources

Sources