Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-85661: excel-mcp-server 0.1.8 can read or change any file

CVE-2026-85661 · published today
Summary

The excel-mcp-server version 0.1.8 does not limit where it can read or write files when a certain setting is missing. This means a malicious user could access or modify any file that the program can reach on the server. Update to a newer version or configure the file path setting to restrict access.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
haris-musa excel-mcp-server <= 0.1.8
Original advisory text
excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Type
CWE-22Path Traversal
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-85661 · MITRE
Monitor software like this
Free during beta