Skip to content

Asana

Disclosed Jun 18, 20251 year agoUnverified

Official notice

Bug in Asana's AI MCP server exposed customer data to other organizations

A logic flaw in the Model Context Protocol server Asana launched on May 1, 2025 for LLM features could expose data from one customer's instance to MCP users at other organizations, limited to each user's access scope. Asana warned users and said it was not the result of a hack.

What is known

People affectedNot stated in the sources we have
DisclosedJun 18, 2025
AttackAI or model
Data exposedInternal documents, Messages
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Source
Asana warns MCP AI feature exposed customer data to other orgsbleepingcomputer.com · News
Asana: security pageasana.com · The organization

Notices filed

WhereFiledPeople
ResearchtotalJun 18, 2025
History of this record
  • 2026-09-25 · source_type: press to company · weekly source
  • 2026-09-25 · source_url: https://www.bleepingcomputer.com/news/security/asana-warns-mcp-ai-feature-exposed-customer-data-to-other-orgs/ to https://asana.com/security · weekly source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Asana

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.