logo

Asana Discloses Data Exposure Bug in MCP Server | UpGuard

ID: b7cd52d9-3387-5660-8f51-9463d85adc0a

STIX ID: report--b7cd52d9-3387-5660-8f51-9463d85adc0a

Feed Name: UpGuard Blog

Threat Score
45/100

Date Published: 2025-08-12

Date Updated: 2026-05-01

...
...

**Executive summary:** On June 4 Asana discovered a bug in its Model Context Protocol (MCP) server that could have exposed data across customer accounts (limited to objects and data visible to the MCP user's permissions); the company took the server offline, fixed the issue, notified potentially affected customers, and offered logs and remediation steps, with no indication of external exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.