← Asana

2025 MCP server bug — cross-org data exposure

2025 Unknown records affected Share on X

Data compromised

Tasks, project metadata, team details, comments, uploaded files

Technical writeup

Logic flaw in Asana's Model Context Protocol (MCP) server allowed user data from one organization to be exposed to users in other organizations. Potentially exposed: tasks, project metadata, team details, comments, files. Bug active May 1–June 4. ~1,000 organizations affected. No evidence of exploitation.

Root cause

Software bug; MCP server logic flaw.

References