logo

Two Lines of Code, Four Million Downloads, Zero Authentication

ID: b5902a7d-e788-5277-8b95-b729a830e50d

STIX ID: report--b5902a7d-e788-5277-8b95-b729a830e50d

Feed Name: NoHackie

Threat Score
82/100

Date Published: 2026-03-09

Date Updated: 2026-04-19

...
...

Pluto Security disclosed two critical vulnerabilities in mcp-atlassian—CVE-2026-27825 (unauthenticated arbitrary file write) and CVE-2026-27826 (SSRF)—which together permit unauthenticated RCE from anyone on the same network by sending two HTTP requests. The flaws affected widely deployed versions (pre-0.17.0) with default network exposure, were patched in v0.17.0, and require immediate patching plus defensive controls (least privilege, bind-to-localhost, enable IMDSv2) and broader MCP ecosystem changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.