Work management MCP server returns one organization's data to another

Organization
Asana
Date
Scale
approximately 1,000 customer organizations notified; cross-tenant exposure possible for roughly five weeks
Surface
Infrastructure
Tools involved
SaaS app
Harm
Data exposure
Who was harmed
Third party
Reversible
No
Root cause
Tenant isolation failure
Prevented by action governance
No
Last verified

Asana launched an opt-in MCP server on 1 May 2025, allowing customers to connect AI assistants to their work management data. A flaw in how the server enforced access control meant that a request scoped to one customer could return records belonging to another. Asana identified the bug on 4 June 2025, took the feature offline the following day, and restored it on 17 June 2025. Roughly 1,000 customer organizations were notified.

The exposure was a logic error rather than an intrusion. No attacker was involved and no credential was misused. Depending on how a given customer had configured the integration and how much their users had queried it, the records reachable across the tenant boundary could include task-level information, project metadata, team details, comments and uploaded files.

Two details are worth preserving precisely. Asana's notices to affected customers describe what could have been exposed rather than confirming what was, and both contemporaneous reporting and the company's own advice to administrators — review MCP access logs, review AI-generated summaries, report anything that appears to belong to another organization — reflect that uncertainty. Asana also issued no public statement, communicating only with the organizations it had identified as affected, so the public record here rests on reporting of those notices rather than on a first-party account.

Sources

  1. 1.
  2. 2.
    Experimental MCP Server Exposed Asana Data
    SANS Institute ·

Sources last verified on .

Related reading