MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825) (CVE-2026-77269) | HOL Guard CVE