GHSA-xv88-r947-5c3vCriticalCVSS 9.8
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is...
🔗 CVE IDs covered (1)
📋 Description
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-85661
- https://github.com/haris-musa/excel-mcp-server/issues/149
- https://github.com/haris-musa/excel-mcp-server
- https://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/server.py
- https://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/validation.py
- https://www.vulncheck.com/advisories/excel-mcp-server-0.1.8-arbitrary-file-read-write-via-stdio-mode
- https://github.com/advisories/GHSA-xv88-r947-5c3v