PT-2026-85554 · Haris Musa · Excel-Mcp-Server

·

CVE-2026-85661

·

Published

2026-09-04

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL FILES PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85661

Affected Products

Excel-Mcp-Server