logo

Asana's cutting-edge AI feature ran into a little data leakage problem

ID: 1c736b33-d416-58dc-aded-41d0d5530b17

STIX ID: report--1c736b33-d416-58dc-aded-41d0d5530b17

Feed Name: The Register (Security)

Threat Score
45/100

Date Published: 2025-06-18

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Asana discovered and fixed a bug in its Model Context Protocol (MCP) server that potentially exposed information from one customer's Asana domain to other MCP users. The vendor took the feature offline from June 5–17, reset all MCP connections, contacted impacted customers, and restored the interface after remediation; there is no indication that the vulnerability was exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.