Path traversal in excel-mcp-server allows unauthenticated remote arbitrary file access
CVE-2026-40576: excel-mcp-server versions up to and including 0.1.7 fail to confine file operations to the EXCEL_FILES_PATH directory, letting an unauthenticated network attacker read, write and overwrite arbitrary files via crafted filepath arguments to any of its 25 MCP tool handlers when run in SSE or Streamable-HTTP mode. Fixed in version 0.1.8.
Disclosed 21 April 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers on the network could read, write and overwrite arbitrary files on the host filesystem, aided by zero authentication on the default network-facing transport and a default bind address of 0.0.0.0.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40576
