VYPR

Office-PowerPoint-MCP-Server

by GongRzhe

CVEs (1)

  • CVE-2025-71427MedOct 1, 2026
    risk 0.37cvss 6.8epss —

    Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse…