Path Traversal Vulnerability in Office PowerPoint MCP Server by GongRzhe
CVE-2025-71427

7.6HIGH

Key Information:

Vendor

Gongrzhe

Vendor
CVE Published:
1 October 2026

What is CVE-2025-71427?

The Office PowerPoint MCP Server up to version 2.0.7 is vulnerable to a path traversal flaw that permits malicious actors to read and write files outside of the designated working directory. By exploiting absolute paths or using directory traversal sequences (e.g., ../), an attacker can manipulate an AI agent via prompt injection. This exploitation allows unauthorized file modifications or the loading of external files through commands like save_presentation and manage_image.

Affected Version(s)

Office-PowerPoint-MCP-Server 0 <= 2.0.7

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sonali Tyagi
.