Sev0AI security incidents, tracked

All incidents / Leaky AI product

Asana's AI connector exposed customer data to other organizations

Asana, disclosed 18 Jun 2025. Leaky AI product Data exposed High

A logic flaw in Asana's new MCP server, which lets AI assistants read Asana data, meant some users could see tasks, projects, comments and files from other companies. Asana took it offline for about two weeks and notified roughly 1,000 potentially affected customers. It says the bug was not the result of an attack.

Disclosed
18 Jun 2025
Organization
Asana
Vendor
Any model
Product
Asana MCP server
Type of AI
AI-powered app
How it happened
Leaky AI product: App flaw
Harm
Data exposed
Data involved
Internal documents
Reach
Many organizations
Records
1,000
Severity
High
Model at fault
No
Status
Confirmed

Sources

  1. https://www.bleepingcomputer.com/news/security/asana-warns-mcp-ai-feature-exposed-customer-data-to-other-orgs/
  2. https://www.upguard.com/blog/asana-discloses-data-exposure-bug-in-mcp-server

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Asana's AI connector exposed customer data to other organizations", https://sev0.fyi/incidents/2025-06-18-asana-mcp-cross-tenant-leak/