excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 0.4%
exploitation probability
0.4%top 62% of all CVEs
observed exploitation
nono source reports it
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
haris-musa · excel-mcp-serverReferences
https://github.com/haris-musa/excel-mcp-serverhttps://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/server.pyhttps://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/validation.pyhttps://github.com/haris-musa/excel-mcp-server/issues/149https://www.vulncheck.com/advisories/excel-mcp-server-0.1.8-arbitrary-file-read-write-via-stdio-mode