CyberRota Analysis
AI-GeneratedThe excel-mcp-server version 0.1.8 is critically vulnerable due to inadequate path confinement in stdio mode when the EXCEL_FILES_PATH variable is not set, enabling attackers to manipulate file paths. This flaw allows unauthorized reading and writing of arbitrary files, potentially exposing sensitive data or compromising system integrity. Organizations utilizing this software should prioritize immediate remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.