Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Path traversal in excel-mcp-server allows unauthenticated remote arbitrary file access

CVE-2026-40576: excel-mcp-server versions up to and including 0.1.7 fail to confine file operations to the EXCEL_FILES_PATH directory, letting an unauthenticated network attacker read, write and overwrite arbitrary files via crafted filepath arguments to any of its 25 MCP tool handlers when run in SSE or Streamable-HTTP mode. Fixed in version 0.1.8.

Disclosed 21 April 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers on the network could read, write and overwrite arbitrary files on the host filesystem, aided by zero authentication on the default network-facing transport and a default bind address of 0.0.0.0.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40576