Skip to main content
Vulnerability Database/CVE-2025-71427

CVE-2025-71427: Office-PowerPoint-MCP-Server Path Traversal

CVE-2025-71427 is a path traversal flaw in Office-PowerPoint-MCP-Server that lets attackers read and write files outside the working directory through prompt injection. This post covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2025-71427 Overview

CVE-2025-71427 is a path traversal vulnerability [CWE-22] in Office-PowerPoint-MCP-Server through version 2.0.7. The server exposes Model Context Protocol (MCP) tools that fail to validate file path parameters before performing read and write operations. Callers can supply absolute paths or ../ sequences to escape the intended working directory. An attacker who steers an AI agent through prompt injection can abuse the save_presentation, open_presentation, or manage_image tools to overwrite any server-writable file or load arbitrary files from the host.

Critical Impact

Prompt-injected AI agents can overwrite arbitrary server-writable files and read sensitive files outside the working directory.

Affected Products

  • Office-PowerPoint-MCP-Server versions up to and including 2.0.7
  • Deployments integrating this MCP server with AI agent frameworks
  • Hosts where the MCP server process has write access to sensitive paths

Discovery Timeline

  • 2026-10-01 - CVE-2025-71427 published to NVD
  • 2026-10-02 - Last updated in NVD database

Technical Details for CVE-2025-71427

Vulnerability Analysis

The Office-PowerPoint-MCP-Server exposes tools that accept user-controlled file path arguments. The save_presentation and manage_image tools accept an output_path parameter, and open_presentation accepts an input path. None of these parameters are canonicalized against the intended working directory before use. Supplying an absolute path such as /etc/cron.d/exploit or a relative path containing ../ sequences causes the server to read or write files anywhere the process has permission.

This vulnerability is particularly relevant for agentic AI workflows. A malicious document, web page, or tool response processed by the AI agent can carry a prompt-injection payload. The injected instructions can direct the agent to invoke MCP tools with crafted paths, turning the AI agent into a confused deputy. Review the VulnCheck Security Advisory for additional context.

Root Cause

The path handling logic in tools/presentation_tools.py and utils/presentation_utils.py passes caller-supplied paths directly to file I/O functions. There is no sandbox check, no canonicalization against an allowed root, and no rejection of absolute paths or .. segments. See the GitHub Code Snippet for the vulnerable routine.

Attack Vector

Exploitation requires an MCP client, typically an AI agent, to invoke a vulnerable tool with an attacker-controlled path. The practical delivery vector is indirect prompt injection: malicious instructions embedded in content the agent processes. The agent then calls save_presentation with a traversal path to overwrite scripts, cron jobs, or SSH authorized keys, or calls open_presentation to exfiltrate file contents into model context. No authentication is required against the MCP server itself in typical local deployments.

Detection Methods for CVE-2025-71427

Indicators of Compromise

  • MCP tool invocations containing absolute paths or ../ sequences in output_path or input path arguments
  • Unexpected writes to sensitive locations such as /etc/, ~/.ssh/, cron directories, or application configuration folders by the MCP server process
  • Reads of files unrelated to presentation workflows, such as /etc/passwd or private key files, through open_presentation
  • New or modified executable files in web roots or startup directories owned by the MCP server account

Detection Strategies

  • Log every MCP tool call with full argument values and alert on paths containing .., drive letters, or leading /
  • Correlate AI agent prompt content with subsequent tool invocations to surface prompt-injection-driven file operations
  • Monitor process-level file access patterns of the Office-PowerPoint-MCP-Server process for writes outside its working directory

Monitoring Recommendations

  • Enable file integrity monitoring on sensitive directories reachable by the MCP server account
  • Capture MCP server stdout, stderr, and audit logs into a centralized log store for retrospective queries
  • Baseline normal file access paths for the server and alert on deviations

How to Mitigate CVE-2025-71427

Immediate Actions Required

  • Upgrade Office-PowerPoint-MCP-Server to a version that incorporates the fix from GitHub Pull Request #33 once released
  • Restrict the MCP server process to a dedicated low-privilege user with no write access outside a sandbox directory
  • Disable or firewall the MCP server if it is exposed to untrusted agents or network callers
  • Review AI agent configurations to limit which MCP tools can be invoked without human confirmation

Patch Information

A fix is proposed in GitHub Pull Request #33 of the Office-PowerPoint-MCP-Server repository. Operators should track the repository for a tagged release above 2.0.7 and update promptly. Until a release is available, apply the patch manually or deploy compensating controls.

Workarounds

  • Run the MCP server inside a container or chroot with only the presentation working directory mounted writable
  • Enforce mandatory access control profiles such as AppArmor or SELinux to confine file reads and writes to an allowlisted path
  • Wrap save_presentation, open_presentation, and manage_image with a proxy that canonicalizes paths and rejects any resolution outside the working directory
  • Require human-in-the-loop approval for any tool call whose path argument contains .. or begins with /
bash
# Configuration example: confine the MCP server to a sandbox directory
mkdir -p /var/lib/pptx-mcp/work
chown mcpuser:mcpuser /var/lib/pptx-mcp/work
chmod 750 /var/lib/pptx-mcp/work

# Launch under a restricted user with a working directory jail
sudo -u mcpuser systemd-run --working-directory=/var/lib/pptx-mcp/work \
  --property=ProtectSystem=strict \
  --property=ProtectHome=yes \
  --property=ReadWritePaths=/var/lib/pptx-mcp/work \
  python -m office_powerpoint_mcp_server

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.