CVE-2025-71427 Overview
CVE-2025-71427 is a path traversal vulnerability [CWE-22] in Office-PowerPoint-MCP-Server through version 2.0.7. The server exposes Model Context Protocol (MCP) tools that fail to validate file path parameters before performing read and write operations. Callers can supply absolute paths or ../ sequences to escape the intended working directory. An attacker who steers an AI agent through prompt injection can abuse the save_presentation, open_presentation, or manage_image tools to overwrite any server-writable file or load arbitrary files from the host.
Critical Impact
Prompt-injected AI agents can overwrite arbitrary server-writable files and read sensitive files outside the working directory.
Affected Products
- Office-PowerPoint-MCP-Server versions up to and including 2.0.7
- Deployments integrating this MCP server with AI agent frameworks
- Hosts where the MCP server process has write access to sensitive paths
Discovery Timeline
- 2026-10-01 - CVE-2025-71427 published to NVD
- 2026-10-02 - Last updated in NVD database
Technical Details for CVE-2025-71427
Vulnerability Analysis
The Office-PowerPoint-MCP-Server exposes tools that accept user-controlled file path arguments. The save_presentation and manage_image tools accept an output_path parameter, and open_presentation accepts an input path. None of these parameters are canonicalized against the intended working directory before use. Supplying an absolute path such as /etc/cron.d/exploit or a relative path containing ../ sequences causes the server to read or write files anywhere the process has permission.
This vulnerability is particularly relevant for agentic AI workflows. A malicious document, web page, or tool response processed by the AI agent can carry a prompt-injection payload. The injected instructions can direct the agent to invoke MCP tools with crafted paths, turning the AI agent into a confused deputy. Review the VulnCheck Security Advisory for additional context.
Root Cause
The path handling logic in tools/presentation_tools.py and utils/presentation_utils.py passes caller-supplied paths directly to file I/O functions. There is no sandbox check, no canonicalization against an allowed root, and no rejection of absolute paths or .. segments. See the GitHub Code Snippet for the vulnerable routine.
Attack Vector
Exploitation requires an MCP client, typically an AI agent, to invoke a vulnerable tool with an attacker-controlled path. The practical delivery vector is indirect prompt injection: malicious instructions embedded in content the agent processes. The agent then calls save_presentation with a traversal path to overwrite scripts, cron jobs, or SSH authorized keys, or calls open_presentation to exfiltrate file contents into model context. No authentication is required against the MCP server itself in typical local deployments.
Detection Methods for CVE-2025-71427
Indicators of Compromise
- MCP tool invocations containing absolute paths or ../ sequences in output_path or input path arguments
- Unexpected writes to sensitive locations such as /etc/, ~/.ssh/, cron directories, or application configuration folders by the MCP server process
- Reads of files unrelated to presentation workflows, such as /etc/passwd or private key files, through open_presentation
- New or modified executable files in web roots or startup directories owned by the MCP server account
Detection Strategies
- Log every MCP tool call with full argument values and alert on paths containing .., drive letters, or leading /
- Correlate AI agent prompt content with subsequent tool invocations to surface prompt-injection-driven file operations
- Monitor process-level file access patterns of the Office-PowerPoint-MCP-Server process for writes outside its working directory
Monitoring Recommendations
- Enable file integrity monitoring on sensitive directories reachable by the MCP server account
- Capture MCP server stdout, stderr, and audit logs into a centralized log store for retrospective queries
- Baseline normal file access paths for the server and alert on deviations
How to Mitigate CVE-2025-71427
Immediate Actions Required
- Upgrade Office-PowerPoint-MCP-Server to a version that incorporates the fix from GitHub Pull Request #33 once released
- Restrict the MCP server process to a dedicated low-privilege user with no write access outside a sandbox directory
- Disable or firewall the MCP server if it is exposed to untrusted agents or network callers
- Review AI agent configurations to limit which MCP tools can be invoked without human confirmation
Patch Information
A fix is proposed in GitHub Pull Request #33 of the Office-PowerPoint-MCP-Server repository. Operators should track the repository for a tagged release above 2.0.7 and update promptly. Until a release is available, apply the patch manually or deploy compensating controls.
Workarounds
- Run the MCP server inside a container or chroot with only the presentation working directory mounted writable
- Enforce mandatory access control profiles such as AppArmor or SELinux to confine file reads and writes to an allowlisted path
- Wrap save_presentation, open_presentation, and manage_image with a proxy that canonicalizes paths and rejects any resolution outside the working directory
- Require human-in-the-loop approval for any tool call whose path argument contains .. or begins with /
# Configuration example: confine the MCP server to a sandbox directory
mkdir -p /var/lib/pptx-mcp/work
chown mcpuser:mcpuser /var/lib/pptx-mcp/work
chmod 750 /var/lib/pptx-mcp/work
# Launch under a restricted user with a working directory jail
sudo -u mcpuser systemd-run --working-directory=/var/lib/pptx-mcp/work \
--property=ProtectSystem=strict \
--property=ProtectHome=yes \
--property=ReadWritePaths=/var/lib/pptx-mcp/work \
python -m office_powerpoint_mcp_server
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.