Security Advisory

CVE-2026-85661

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-04 14:32:18
Last updated 2026-09-04 14:32:18
Assigner VulnCheck
CVSS score 9.8
State PUBLISHED

Description

excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.