PT-2026-64026 · Unknown · Office-Word-Mcp-Server
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Office-Word-MCP-Server versions prior to 1.1.12
Description
A path traversal issue exists in the document tools. Attackers who can influence the
filename argument can read arbitrary .docx files or create and overwrite .docx files outside the intended working directory. This is possible by supplying absolute paths or ../ traversal sequences to document open and save operations, which bypasses the check file writeable() and ensure docx extension() helpers because they lack base-directory confinement or realpath validation.Recommendations
Update Office-Word-MCP-Server to version 1.1.12 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office-Word-Mcp-Server