VYPR

excel-mcp-server

by Haris Musa

CVEs (1)

  • CVE-2026-85661CriSep 4, 2026
    risk 0.64cvss 9.8epss

    excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.