Description
Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.
Published: 2026-10-01
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: File write and read beyond intended directory
Action: Immediate Patch
AI Analysis

Impact

Office-PowerPoint-MCP-Server versions up to 2.0.7 contain a path traversal flaw that permits callers to supply arbitrary paths for the "output_path" parameter used with the save_presentation, open_presentation, and manage_image operations. By manipulating this parameter with absolute paths or "../" sequences the attacker can cause the server to write files outside its working directory, overwrite existing server‑writable files, and read arbitrary files. The vulnerability can lead to data exfiltration, configuration tampering, or potentially remote code execution if the overwritten files influence server behavior.

Affected Systems

This flaw affects the GongRzhe Office‑PowerPoint‑MCP‑Server distribution. All released versions through 2.0.7 are vulnerable; no lower‑version information is provided, nor are later releases confirmed to be fixed. Systems running any of these versions on a machine where the service runs with write privileges to the server file system are impacted.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity risk, and the vulnerability is reachable through normal server interactions, so an attacker with network access to the MCP interface can attempt exploitation. The EPSS score is not available, suggesting limited public exploitation data, and the vulnerability has not been listed in CISA’s KEV catalog. Nonetheless, the attack vector likely involves sending crafted RPC or HTTP requests to the MCP service, making this threat relevant for exposed servers. The impact can be serious if an attacker can overwrite configuration or executable files, so the risk remains significant.

Generated by OpenCVE AI on October 2, 2026 at 00:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Office-PowerPoint-MCP-Server release from the official GitHub project, which includes an input validation patch for the output_path parameter.
  • If an upgrade is not immediately possible, modify the source code to normalize and validate the output_path, rejecting absolute paths and any directory traversal sequences before the file operation is performed.
  • As a temporary containment measure, run the MCP service under a least‑privilege user that has write access only to a dedicated subdirectory, or employ a chroot/jail to limit the file system visible to the service.

Generated by OpenCVE AI on October 2, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.
Title Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_image
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T22:53:04.500Z

Reserved: 2026-10-01T21:54:20.902Z

Link: CVE-2025-71427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T23:16:46.613

Modified: 2026-10-01T23:16:46.613

Link: CVE-2025-71427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T00:30:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')