excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.3epss 0.4%
probabilidad de explotación
0.4%top 62% de las CVE
explotación observada
noninguna fuente lo reporta
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
haris-musa · excel-mcp-serverReferencias
https://github.com/haris-musa/excel-mcp-serverhttps://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/server.pyhttps://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/validation.pyhttps://github.com/haris-musa/excel-mcp-server/issues/149https://www.vulncheck.com/advisories/excel-mcp-server-0.1.8-arbitrary-file-read-write-via-stdio-mode