CVE-2026-85661

excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.

  • Published Sep 4, 2026
  • CVSS 9.3 critical
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-85661 at the National Vulnerability Database