Beveiligingsadvies

CVE-2026-85661

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-04 14:32:18
Laatst bijgewerkt 2026-09-04 14:32:18
Toegewezen door VulnCheck
CVSS-score 9.8
Status PUBLISHED

Beschrijving

excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.