A vulnerability identified as problematic has been detected in sooperset mcp-atlassian up to 0.21.x. This vulnerability affects the function _upload_attachment_direct of the file src/mcp_atlassian/confluence/attachments.py of the component Attachments. This manipulation of the argument file_path causes path traversal.

This vulnerability appears as CVE-2026-73498. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.