CVE-2026-85661
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
Açıklama ve Etki
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
Referanslar
- https://github.com/haris-musa/excel-mcp-server
- https://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/server.py
- https://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/validation.py
- https://github.com/haris-musa/excel-mcp-server/issues/149
- https://www.vulncheck.com/advisories/excel-mcp-server-0.1.8-arbitrary-file-read-write-via-stdio-mode
Güvenli Doğrulama Notu
Bu sayfa saldırı gerçekleştiren payload'lar çalıştırmaz. Doğrulama; etkilenen ürün/sürümün envanterden kontrol edilmesi, üretici güvenlik duyurusunun incelenmesi ve güncellemenin uygulanması üzerinden yapılmalıdır.