Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-85661: excel-mcp-server 0.1.8 can read or change any file
CVE-2026-85661 · published today
Summary
The excel-mcp-server version 0.1.8 does not limit where it can read or write files when a certain setting is missing. This means a malicious user could access or modify any file that the program can reach on the server. Update to a newer version or configure the file path setting to restrict access.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| haris-musa | excel-mcp-server | <= 0.1.8 |
Original advisory text
excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
References
- https://github.com/haris-musa/excel-mcp-server product
- https://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/server.... technical-description
- https://github.com/haris-musa/excel-mcp-server/issues/149 issue-tracking
- https://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/validat... technical-description
- https://www.vulncheck.com/advisories/excel-mcp-server-0.1.8-arbitrary-file-read-... third-party-advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Type
CWE-22Path Traversal
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Monitor software like this
Free during beta