Rust-based Zed extension that launches the upstream [`mcp-atlassian`](https://github.com/sooperset/mcp-atlassian) server for Jira/Confluence.
MCPpedia last refreshed this data
This server has been archived and is no longer actively maintained.
Zed MCP Server Jira is an MCP server that rust-based Zed extension that launches the upstream [`mcp-atlassian`](https://github.com/sooperset/mcp-atlassian) server for Jira/Confluence. Its tool list has not been published yet over stdio and http, requires no API key, and scores 41/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients - only the file and path differ.
{
"mcpServers": {
"zed-mcp-server-jira": {
"args": [
"mcp-atlassian"
],
"command": "uvx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Rust-based Zed extension that launches the upstream mcp-atlassian server for Jira/Confluence.
Run this in your terminal to verify the server starts. Then let us know if it worked - your result helps other developers.
uvx 'mcp-atlassian' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories - click any category to see the underlying evidence.
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
### Summary `confluence_upload_attachment` passes `file_path` directly to `open(file_path, "rb")` with no path validation. Any authenticated MCP client — or an AI agent manipulated via prompt injection — can read any file the server process can access and exfiltrate it to Confluence as an attachment. ### Details Root cause: `src/mcp_atlassian/confluence/attachments.py`, `_upload_attachment_direct()`: ```python files = {"file": (filename, open(file_path, "rb"))} # no validate_safe_path() ```
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
### Summary An unauthenticated attacker who can reach the mcp-atlassian HTTP endpoint can force the server process to make outbound HTTP requests to an arbitrary attacker-controlled URL by supplying two custom HTTP headers without an `Authorization` header. No authentication is required. The vulnerability exists in the HTTP middleware and dependency injection layer — not in any MCP tool handler - making it invisible to tool-level code analysis. In cloud deployments, this could enable theft of IA
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
### Summary `confluence_upload_attachment` passes `file_path` directly to `open(file_path, "rb")` with no path validation. Any authenticated MCP client — or an AI agent manipulated via prompt injection — can read any file the server process can access and exfiltrate it to Confluence as an attachment. ### Details Root cause: `src/mcp_atlassian/confluence/attachments.py`, `_upload_attachment_direct()`: ```python files = {"file": (filename, open(file_path, "rb"))} # no validate_safe_path() ```
mcp-atlassian: Arbitrary server-side file read via attachment upload
### Summary A client that can invoke MCP tools can read **arbitrary files from the server host** and exfiltrate them as Atlassian attachments. The attachment-upload tools take a client-supplied `file_path` and `open()` it on the **server's** filesystem. The upload tools are meant to attach a file from the **caller's** environment — the client supplies a path expecting it to refer to its own machine. Over a remote transport (HTTP/SSE) that path is instead resolved and read on the server, and th
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
### Summary GHSA-7r34-79r5-rcc9's fix added `validate_url_for_ssrf`, which resolves the attacker-controlled `X-Atlassian-{Jira,Confluence}-Url` header host **once at middleware time** and trusts the result. But the outbound request is later built with the **raw hostname** and **re-resolves at connect time with no IP pinning**. An attacker-controlled rebinding DNS name returns a public IP on the guard's lookup (validation passes) and `169.254.169.254` / an internal IP on the request's lookup (the
Be the first to review
Have you used this server?
Share your experience - it helps other developers decide.
Sign in to write a review.
Others in developer-tools / productivity
Manage Supabase projects — databases, auth, storage, and edge functions
MCP server for using the GitLab API
XcodeBuildMCP provides tools for Xcode project management, simulator management, and app utilities.
MCP server for enterprise local codebase indexing, semantic search, and code dependency graphs.
MCP Security Weekly
Get CVE alerts and security updates for Zed Mcp Server Jira and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.