CVE-2026-85661
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
- Published Sep 4, 2026
- CVSS 9.3 critical
- 0.7% chance of exploitation in the next 30 days (EPSS)