CVE Explorer
CVE-2026-40576
excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated attacker on the network can read, write, and overwrite arbitrary files on the host filesystem by supplying crafted filepath arguments to any of the 25 exposed MCP tool handlers. The server is intended t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"excel-mcp-server","vendor":"haris-musa","versions":[{"status":"affected","version":"< 0.1.8"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b1835d06d7c8eb4b6803198ea7c0b4b7141b5835f6e81c511334192e623a990f · sha256:a26ec246e55de1cf… · /containers/cna/affected/0
Provider-owned CVSS observations
2 source assertions{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.4,"baseSeverity":"CRITICAL","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b1835d06d7c8eb4b6803198ea7c0b4b7141b5835f6e81c511334192e623a990f · sha256:a26ec246e55de1cf… · /containers/cna/metrics/0/cvssV3_1
{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.4,"baseSeverity":"CRITICAL","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b1835d06d7c8eb4b6803198ea7c0b4b7141b5835f6e81c511334192e623a990f · sha256:a26ec246e55de1cf… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b1835d06d7c8eb4b6803198ea7c0b4b7141b5835f6e81c511334192e623a990f · sha256:a26ec246e55de1cf… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/haris-musa/excel-mcp-server/security/advisories/GHSA-j98m-w3xp-9f56","tags":["x_refsource_CONFIRM"],"url":"https://github.com/haris-musa/excel-mcp-server/security/advisories/GHSA-j98m-w3xp-9f56"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b1835d06d7c8eb4b6803198ea7c0b4b7141b5835f6e81c511334192e623a990f · sha256:a26ec246e55de1cf… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/haris-musa/excel-mcp-server/security/advisories/GHSA-j98m-w3xp-9f56"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b1835d06d7c8eb4b6803198ea7c0b4b7141b5835f6e81c511334192e623a990f · sha256:a26ec246e55de1cf… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.