Asana Discloses Data Exposure Bug in MCP Server | UpGuard
ID: b7cd52d9-3387-5660-8f51-9463d85adc0a
STIX ID: report--b7cd52d9-3387-5660-8f51-9463d85adc0a
Feed Name: UpGuard Blog
Threat Score
**Executive summary:** On June 4 Asana discovered a bug in its Model Context Protocol (MCP) server that could have exposed data across customer accounts (limited to objects and data visible to the MCP user's permissions); the company took the server offline, fixed the issue, notified potentially affected customers, and offered logs and remediation steps, with no indication of external exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
