Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Haris-musa
Haris-musa excel-mcp-server |
|
| Vendors & Products |
Haris-musa
Haris-musa excel-mcp-server |
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process. | |
| Title | excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T14:32:18.828Z
Reserved: 2026-09-04T13:32:27.956Z
Link: CVE-2026-85661
No data.
Status : Received
Published: 2026-09-04T15:17:43.643
Modified: 2026-09-04T15:17:43.643
Link: CVE-2026-85661
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:52:41Z