Impact
Office-PowerPoint-MCP-Server versions up to 2.0.7 contain a path traversal flaw that permits callers to supply arbitrary paths for the "output_path" parameter used with the save_presentation, open_presentation, and manage_image operations. By manipulating this parameter with absolute paths or "../" sequences the attacker can cause the server to write files outside its working directory, overwrite existing server‑writable files, and read arbitrary files. The vulnerability can lead to data exfiltration, configuration tampering, or potentially remote code execution if the overwritten files influence server behavior.
Affected Systems
This flaw affects the GongRzhe Office‑PowerPoint‑MCP‑Server distribution. All released versions through 2.0.7 are vulnerable; no lower‑version information is provided, nor are later releases confirmed to be fixed. Systems running any of these versions on a machine where the service runs with write privileges to the server file system are impacted.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity risk, and the vulnerability is reachable through normal server interactions, so an attacker with network access to the MCP interface can attempt exploitation. The EPSS score is not available, suggesting limited public exploitation data, and the vulnerability has not been listed in CISA’s KEV catalog. Nonetheless, the attack vector likely involves sending crafted RPC or HTTP requests to the MCP service, making this threat relevant for exposed servers. The impact can be serious if an attacker can overwrite configuration or executable files, so the risk remains significant.
OpenCVE Enrichment