top of page
perceptive_background_267k.jpg

excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and in…

Published:

20 april 2026 om 22:00:00

Alert date:

21 april 2026 om 18:10:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A path traversal vulnerability in excel-mcp-server versions up to 0.1.7 allows unauthenticated remote attackers to read, write, and overwrite arbitrary files on the host filesystem. The vulnerability occurs when running in SSE or Streamable-HTTP transport mode, where attackers can supply crafted filepath arguments to any of the 25 exposed MCP tool handlers. The server's get_excel_path() function fails to properly enforce directory boundaries by passing absolute paths without validation and joining relative paths without resolution. Combined with zero authentication and default binding to all interfaces (0.0.0.0), this enables trivial remote exploitation. The vulnerability is fixed in version 0.1.8.

Technical details

Mitigation steps:

Affected products:

excel-mcp-server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page