Arbitrary File Access Vulnerability in Excel MCP Server by Haris Musa
CVE-2026-85661
9.3CRITICAL
What is CVE-2026-85661?
The excel-mcp-server version 0.1.8 contains a flaw in stdio mode where it fails to enforce necessary path confinement when EXCEL_FILES_PATH is not set. This vulnerability permits an attacker to supply unchecked file paths, thereby allowing unauthorized reading from and writing to arbitrary files. This capability could lead to serious information disclosure and data integrity issues as the attacker can manipulate files accessible to the process, heightening the risk of exploitation in environments that rely on this server.
Affected Version(s)
excel-mcp-server 0 <= 0.1.8
