Arbitrary File Access Vulnerability in Excel MCP Server by Haris Musa
CVE-2026-85661

9.3CRITICAL

Key Information:

Vendor

Haris-musa

Vendor
CVE Published:
4 September 2026

What is CVE-2026-85661?

The excel-mcp-server version 0.1.8 contains a flaw in stdio mode where it fails to enforce necessary path confinement when EXCEL_FILES_PATH is not set. This vulnerability permits an attacker to supply unchecked file paths, thereby allowing unauthorized reading from and writing to arbitrary files. This capability could lead to serious information disclosure and data integrity issues as the attacker can manipulate files accessible to the process, heightening the risk of exploitation in environments that rely on this server.

Affected Version(s)

excel-mcp-server 0 <= 0.1.8

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.