excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Haris-musa
Haris-musa excel-mcp-server |
|
| Vendors & Products |
Haris-musa
Haris-musa excel-mcp-server |
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process. | |
| Title | excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-04T14:32:18.828Z
Updated: 2026-09-04T14:32:18.828Z
Reserved: 2026-09-04T13:32:27.956Z
Link: CVE-2026-85661
No data.
Status : Received
Published: 2026-09-04T15:17:43.643
Modified: 2026-09-04T15:17:43.643
Link: CVE-2026-85661
No data.