4 Sources
[1]
Asana MCP server back online after plugging a data-leak hole
Asana has fixed a bug in its Model Context Protocol (MCP) server that could have allowed users to view other organizations' data, and the experimental feature is back up and running after nearly two weeks of downtime to fix the issue. MCP is an open-source protocol first introduced by Anthropic in
[2]
Asana warns MCP AI feature exposed customer data to other orgs
Work management platform Asana is warning users of its new Model Context Protocol (MCP) feature that a flaw in its implementation potentially led to data exposure from their instances to other users and vice versa. The data exposure was due to a logic flaw in the MCP system and not the result of a
[3]
Researcher finds 184 million unique credentials in unsecured database including bank, health, government, and major tech platform logins
Asana AI-powered tool had a bug which exposed user data to other users Popular project management platform Asana is warning users a newly-introduced tool may have leaked their data to others on the service Research from security experts UpGuard noted in early May 2025, Asana introduced Model
[4]
Asana bug in new AI feature may have exposed data to other users for weeks
What to know about the Asana bug. Credit: Cheng Xin / Getty Images A bug in one of Asana's new AI features made user information accessible to other users for several weeks. The company said the issue was resolved and it was the result of a malicious hack. Instead, it appeared to be a logic flaw
Share
Copy Link
Asana's Model Context Protocol (MCP) server, an AI integration feature, experienced a bug that potentially exposed user data to other organizations. The incident affected approximately 1,000 customers and raises concerns about data privacy in AI-powered tools.
Asana, a popular project management platform, recently faced a significant security issue with its newly introduced Model Context Protocol (MCP) server. The bug, discovered on June 4, 2025, potentially exposed user data to other organizations for over a month, affecting approximately 1,000 customers
1
2
.The MCP server, launched on May 1, 2025, is an open-source protocol that allows AI agents and language models to interact with external sources, including databases and messaging platforms
1
. Asana implemented this feature to enable users to integrate their Asana data with other AI applications and use natural language queries to access enterprise data1
.However, a logic flaw in the MCP system implementation led to a data exposure risk. The bug could have allowed users to view information from other organizations' Asana domains, limited to each user's access scope
2
3
.
Source: BleepingComputer
While Asana has not provided detailed information about the coding error, the potential data exposure could include:
2
The extent of the exposure depended on the integration type and engagement with the chatbots. It's important to note that organizations did not have their entire Asana workspace leaked to the public
2
.Upon discovering the vulnerability, Asana took immediate action:
1
.1
.1
3
.As of June 18, the MCP interface is back online, but customers need to manually reconnect their Asana instances to the server
1
.
Source: Mashable
This incident serves as a crucial reminder of the potential risks associated with integrating emerging AI technologies into existing platforms. Greg Pollock, director of research and insights at UpGuard, emphasized key lessons for organizations integrating Large Language Models (LLMs):
1
.1
.Related Stories
In light of this incident, security experts recommend that Asana users take the following precautions:
2
.2
.3
.2
.
Source: TechRadar
This incident highlights the growing concerns surrounding data privacy and security in the age of AI integration. As companies rush to implement AI-powered features, it's crucial to maintain robust security measures and consider the potential risks of data exposure
4
.The Asana bug serves as a reminder that even well-established platforms can face significant challenges when implementing new AI technologies. As the adoption of AI continues to accelerate across industries, organizations must prioritize security and privacy considerations to protect sensitive user data and maintain trust in their platforms.
Summarized by
Navi
[1]
[2]
17 Apr 2026•Technology

16 Jul 2025•Technology

20 Jan 2026•Technology

1
Technology

2
Science and Research

3
Technology
