2025 MCP server bug — cross-org data exposure
Data compromised
Tasks, project metadata, team details, comments, uploaded files
Technical writeup
Logic flaw in Asana's Model Context Protocol (MCP) server allowed user data from one organization to be exposed to users in other organizations. Potentially exposed: tasks, project metadata, team details, comments, files. Bug active May 1–June 4. ~1,000 organizations affected. No evidence of exploitation.
Root cause
Software bug; MCP server logic flaw.