Medium severity6.8NVD Advisory· Published Oct 1, 2026
CVE-2025-71427
CVE-2025-71427
Description
Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.
Affected products
1- Range: <=2.0.7
Patches
Vulnerability mechanics
References
4- github.com/GongRzhe/Office-PowerPoint-MCP-Server/blob/3631ba2ec0c24504476f78bf74d329c9be11caaa/tools/presentation_tools.pynvd
- github.com/GongRzhe/Office-PowerPoint-MCP-Server/blob/3631ba2ec0c24504476f78bf74d329c9be11caaa/utils/presentation_utils.pynvd
- github.com/GongRzhe/Office-PowerPoint-MCP-Server/pull/33nvd
- www.vulncheck.com/advisories/office-powerpoint-mcp-server-through-2.0.7-path-traversal-via-save-presentation-and-manage-imagenvd
News mentions
0No linked articles in our index yet.