excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Haris-musa
Haris-musa excel-mcp-server |
|
| Vendors & Products |
Haris-musa
Haris-musa excel-mcp-server |
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process. | |
| Title | excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T14:32:18.828Z
Reserved: 2026-09-04T13:32:27.956Z
Link: CVE-2026-85661
No data.
Status : Received
Published: 2026-09-04T15:17:43.643
Modified: 2026-09-04T15:17:43.643
Link: CVE-2026-85661
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:52:41Z
Weaknesses