Asana’s 2025 MCP data exposure.

A source-linked record of the implementation flaw in Asana’s Model Context Protocol feature that could make some data from one customer organization visible to a user in another, including the conditional scope and Asana’s response. [1][2]

Data exposure Published Last fact-checked 4 cited sources Research by SealTask

The short answer

Asana disclosed that a flaw in its Model Context Protocol implementation potentially made certain information in some customer instances accessible to users from other Asana customers. Asana described the event as a logic or implementation flaw, not an external hack into its systems. [1][2]

The feature launched on May 1, 2025, Asana discovered the issue on June 4, and reporting said roughly 1,000 customers could have been affected. Asana took the feature offline, sent notices to impacted organizations, and its status page showed the feature back to normal operation on June 17. The public sources describe potential access; they do not establish that every potentially exposed record was actually viewed by another customer. [1][2]

This record covers the cross-customer data-exposure risk in Asana’s Model Context Protocol feature between May and June 2025. It does not establish that Asana’s wider service was breached or that every customer workspace was exposed. [1][2]

Classification: Data became accessible to unintended people because of a bug or configuration error. Learn how incident terms differ.

Classification

Cross-customer data exposure caused by an MCP implementation flaw; not a confirmed external intrusion [1][2]

Feature window

MCP launched May 1, 2025; issue discovered June 4; status returned to normal June 17 [2]

Potential reach

Roughly 1,000 customers, according to an Asana spokesperson quoted by BleepingComputer [2]

Possible data

Task information, project metadata, team details, comments or discussions, and uploaded files within the affected user’s existing access scope [2]

Publicly established impact

Potential unintended access; the cited disclosures do not quantify confirmed cross-customer views [1][2]

Response

Feature taken offline, impacted organizations notified, status returned to normal operation June 17 [2]

Incident timeline.

  1. Asana launches its MCP feature

    Asana makes the feature available so AI tools can interact with Asana data under a user’s permissions. The later-disclosed implementation flaw is present during this release window. [2]

  2. Issue discovered and feature taken offline

    Asana identifies the logic flaw and disables MCP while investigating whether data from one customer organization could be returned to a user associated with another. [1][2]

  3. MCP returns to normal operation

    Asana’s status page shows MCP returning to normal operation. Reporting says Asana sent notices with communication-form links to each impacted organization. [2]

  4. Asana describes the issue in an SEC filing

    Asana’s quarterly filing records that a June 2025 MCP implementation flaw potentially made certain data in some customer instances accessible to other users of the feature. [1]

What happened in Asana’s MCP feature

Model Context Protocol connectors let an AI client request data from another service. In Asana’s implementation, a logic flaw could cross the customer boundary: a request made by a user from one organization could potentially receive information from another customer instance. This was an authorization and data-isolation failure in the feature, rather than evidence that an attacker broke into Asana infrastructure. [1][2]

Asana’s SEC filing uses conditional language: certain data was “potentially” accessible. BleepingComputer likewise reported possible exposure and said Asana did not characterize the incident as a hack. The sources do not support treating every customer in the estimated population as having confirmed data access by another organization. [1][2]

What data could have crossed the customer boundary

According to notices described by BleepingComputer, possible data included task-level information, project metadata, team details, comments or discussions, and uploaded files. Access remained tied to what the affected Asana user was already authorized to reach; the incident was not described as making an entire workspace public. [2]

An Asana spokesperson told BleepingComputer that roughly 1,000 customers could have been affected. That estimate is the potential customer population reported publicly, not a count of confirmed data disclosures or individual records viewed. [2]

Asana’s response

Asana took MCP offline after discovering the issue on June 4, sent notices with communication-form links to impacted organizations, and returned the feature to normal operational status on June 17. [2]

Customers evaluating the event should preserve the distinction between potential and observed access. The public materials identify the vulnerable window and data classes but do not provide a public per-customer audit of which records, if any, another organization actually retrieved. [1][2]

What Asana customers should review

Organizations that received an Asana notice should use its stated affected-data categories as the starting point, then review connected AI clients, MCP access, user permissions, and any sensitive files or conversations within the named scope. Affected organizations may also need to assess their own notification or contractual duties based on the data they stored. [2]

The event is also a reason to treat AI connectors as an authorization boundary, not merely an interface feature. Limit connector access to the users and projects that need it, and retain logs capable of showing which resources a connected client requested. [1][2]

How SealTask relates to this incident class

Cross-customer disclosure of readable workspace content is the incident class most relevant to SealTask’s client-side encryption. SealTask stores protected task content as ciphertext, which can reduce what a passive server-side stored-data disclosure reveals. That property does not prove it would have prevented every path in Asana’s MCP incident, and it does not protect server-visible metadata, account access, authorized clients, active sessions, or compromised devices. [4]

Frequently asked questions.

Was Asana hacked in 2025?

The cited disclosures describe an implementation or logic flaw in Asana’s MCP feature, not an external hack into Asana systems. The flaw could potentially return some customer data to a user from another customer organization. [1][2]

How many Asana customers were affected?

An Asana spokesperson told BleepingComputer that roughly 1,000 customers could have been affected. That is a potential-scope estimate, not a count of confirmed cross-customer data views. [2]

What Asana data could have been exposed?

Reported categories included task information, project metadata, team details, comments or discussions, and uploaded files, bounded by the affected user’s existing permissions. [2]

When did Asana restore the MCP feature?

Asana discovered and disabled the affected feature on June 4, 2025. Its status page returned to normal operational status on June 17; the cited public sources do not describe further verification steps. [2]

Is Asana listed in Have I Been Pwned?

No product-attributed Asana entry was located in the live HIBP breached-sites index on July 13, 2026. That is only an HIBP coverage observation and does not negate this separately disclosed MCP data exposure. [3][1]

Sources

All sources last accessed . Corrections: email hello@sealtask.com with a source and we will review and correct.

  1. 01
    Asana Form 10-Q for the quarter ended July 31, 2025 - Primary company filing — the June 2025 MCP implementation flaw and its conditional cross-user scope
  2. 02
    BleepingComputer: “Asana warns MCP AI feature exposed customer data to other orgs” - Contemporaneous reporting — launch and restoration dates, potential customer count, and possible data categories
  3. 03
    Have I Been Pwned: breached-sites index - No product-attributed Asana entry located; checked against the live index on July 13, 2026
  4. 04
    SealTask security architecture - What SealTask encrypts client-side and which account and operational metadata remain server-visible

Prefer task content protected at rest?

SealTask encrypts task titles, notes, comments, and attachments before upload. A compromise limited to stored server data would expose ciphertext for that content; account metadata, active sessions, client delivery, and devices remain separate risks.