Path Traversal Vulnerability in ishayoyo Excel-MCP - Affected Product by ishayoyo
CVE-2026-10278
Key Information:
Badges
What is CVE-2026-10278?
A path traversal vulnerability exists in the ishayoyo Excel-MCP component, specifically in the read_file/write_file feature located in src/index.ts, exposing it to potential unauthorized access to filesystem locations. By manipulating the filePath or outputPath arguments, an attacker can exploit this flaw remotely. The vulnerability has been publicly disclosed, and despite prior notification to the developers, no remediation steps have been undertaken yet.
Affected Version(s)
excel-mcp 1.0.0
excel-mcp 1.0.1
excel-mcp 1.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
