SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-85661

CRITICAL · CVSS 9.8 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The excel-mcp-server version 0.1.8 is critically vulnerable due to inadequate path confinement in stdio mode when the EXCEL_FILES_PATH variable is not set, enabling attackers to manipulate file paths. This flaw allows unauthorized reading and writing of arbitrary files, potentially exposing sensitive data or compromising system integrity. Organizations utilizing this software should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85661
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%

Original NVD Description

excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.