Impact
This vulnerability occurs in excel‑mcp‑server 0.1.8 when the environment variable EXCEL_FILES_PATH is not set. The program fails to enforce path confinement in stdio mode, allowing an attacker to provide arbitrary file paths to the read and write utilities. As a result the attacker can read from or write to any file that the server process can access.
Affected Systems
The affected product is excel‑mcp‑server version 0.1.8 from vendor haris‑musa. No other product or version combinations are currently identified as vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a severe risk. EPSS is not available, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker supplying malicious file paths to the server via stdio mode, which can be performed locally or remotely if the service accepts external connections. Successful exploitation lets an attacker read sensitive data or modify arbitrary files, potentially compromising confidentiality, integrity, and availability of the system.
OpenCVE Enrichment