Asana's AI connector exposed customer data to other organizations
A logic flaw in Asana's new MCP server, which lets AI assistants read Asana data, meant some users could see tasks, projects, comments and files from other companies. Asana took it offline for about two weeks and notified roughly 1,000 potentially affected customers. It says the bug was not the result of an attack.
- Disclosed
- 18 Jun 2025
- Organization
- Asana
- Vendor
- Any model
- Product
- Asana MCP server
- Type of AI
- AI-powered app
- How it happened
- Leaky AI product: App flaw
- Harm
- Data exposed
- Data involved
- Internal documents
- Reach
- Many organizations
- Records
- 1,000
- Severity
- High
- Model at fault
- No
- Status
- Confirmed