Unknown · Office-Powerpoint-Mcp-Server · CVE-2025-71427
**Name of the Vulnerable Software and Affected Versions**
Office-PowerPoint-MCP-Server versions prior to 2.0.8
**Description**
A path traversal issue allows callers to read and write files outside the intended working directory by using absolute paths or `../` sequences. An attacker can use prompt injection to manipulate an AI agent into abusing the `save presentation()`, `open presentation()`, or `manage image()` functions via the `output path` variable to overwrite server-writable files or load external files.
**Recommendations**
Update Office-PowerPoint-MCP-Server to version 2.0.8 or later.
As a temporary mitigation, restrict the use of the `output path` variable in the `save presentation()`, `open presentation()`, and `manage image()` functions.