2025-06-23
Asana Fixes Vulnerability in MCP Server Feature
Asana has fixed a vulnerability in their implementation of the Model Context Protocol (MCP) artificial intelligence integration protocol that could have been exploited to see data belonging to other organizations. Asana introduced the opt-in MCP server feature at the beginning of May 2025, and disabled the use of MCP from June 5 through 17 while addressing the issue. Asana writes that "as part of [their] remediation efforts, [they] reset all connections to the MCP server. This means [users will] need to manually reconnect [their] Asana instance to the MCP server."
Editor's Note
This is the proverbial tip of the iceberg for MCP attacks, this one being associated with a logic flaw yielding some level of cross-tenant access. Look for many, many more of these in coming years. And for our penetration testing friends out there - get smart on this stuff fast and integrate it into your testing regimen. You'll need it! This is especially important in verifying authorization of access when using AI features. In his keynote speech at the RSAC Conference this year, SANS Fellow Josh Wright spoke of "Authorization Sprawl.' AI features enabled with MCP are one way attackers can find and exploit authorization sprawl, as indicated in this Asana issue.

Ed Skoudis
The flaw allowed a user to access their allowed data types from other customers, due to incomplete access control enforcement. You need to have your Asana admin review logs for MCP access, review AI generated summaries/answers, and report immediately any data which appear to be from another organization. Review the recommendations from UpGuard (https://www.upguard.com/blog/asana-discloses-data-exposure-bug-in-mcp-server) before (re)integrating LLMs into sensitive workflows.

Lee Neely
Read more in
BleepingComputer: Asana warns MCP AI feature exposed customer data to other orgs
The Register: Asana's cutting-edge AI feature ran into a little data leakage problem
Gov Infosecurity: Asana Fixes Security Flaw in AI Data Integration Tool