Skip to main content
Vulnerability Database/CVE-2026-85661

CVE-2026-85661: excel-mcp-server Path Traversal Vulnerability

CVE-2026-85661 is a path traversal flaw in excel-mcp-server 0.1.8 that allows attackers to read and write arbitrary files when EXCEL_FILES_PATH is unset. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-85661 Overview

CVE-2026-85661 is a path traversal vulnerability [CWE-22] in excel-mcp-server version 0.1.8. The server fails to enforce path confinement in stdio mode when the EXCEL_FILES_PATH environment variable is unset. Attackers can supply unchecked file paths to the read and write tools, allowing arbitrary file access on the host. The flaw affects Model Context Protocol (MCP) integrations that expose Excel file operations to AI agents or automation clients. Successful exploitation permits reading and writing any file accessible to the process user.

Critical Impact

Attackers can read and write arbitrary files on the host, enabling credential theft, configuration tampering, and potential code execution through overwritten scripts or startup files.

Affected Products

  • excel-mcp-server version 0.1.8
  • Deployments running in stdio mode
  • Instances where EXCEL_FILES_PATH is unset

Discovery Timeline

  • 2026-09-04 - CVE-2026-85661 published to the National Vulnerability Database (NVD)
  • 2026-09-04 - Last updated in NVD database

Technical Details for CVE-2026-85661

Vulnerability Analysis

The excel-mcp-server project exposes Excel file operations through the Model Context Protocol. In stdio mode, the server relies on the EXCEL_FILES_PATH environment variable to define a base directory for file operations. When this variable is unset, the server accepts caller-supplied absolute or relative paths without confinement checks.

The read and write tool handlers pass user-controlled paths directly to file operations. No canonicalization or prefix validation restricts access to a sandboxed directory. As a result, requests containing paths such as /etc/passwd or ../../home/user/.ssh/id_rsa are processed against the process user's file system privileges. This behavior maps to CWE-22: Improper Limitation of a Pathname to a Restricted Directory.

Root Cause

The root cause is the absence of path confinement logic when EXCEL_FILES_PATH is not configured. The validation routines in validation.py do not enforce a mandatory base directory, and server.py does not reject unbounded paths in stdio mode. Reviewers can inspect the affected code in the server.py source and validation.py source.

Attack Vector

An attacker with the ability to send MCP tool invocations to the stdio-mode server supplies a crafted file path to a read or write tool. The server opens or writes the target file using the process user's privileges. Attack scenarios include reading SSH keys, cloud credentials, and configuration files, or overwriting shell startup scripts and application files. Additional context is available in the VulnCheck advisory and GitHub issue #149.

Detection Methods for CVE-2026-85661

Indicators of Compromise

  • Read or write tool invocations containing absolute paths outside an expected workbook directory.
  • Requests containing traversal sequences such as ../ or references to /etc/, ~/.ssh/, or cloud credential paths.
  • Access to sensitive files by the excel-mcp-server process user in file system audit logs.
  • Unexpected modifications to .bashrc, .profile, or application configuration files on hosts running the server.

Detection Strategies

  • Inspect MCP transport logs for tool call arguments referencing paths outside the intended workbook directory.
  • Enable file system auditing (auditd on Linux, Object Access auditing on Windows) for the process user account.
  • Alert on excel-mcp-server processes opening files in /etc, home directory dotfiles, or credential stores.

Monitoring Recommendations

  • Log every file path passed to read and write tools and forward the logs to a centralized SIEM.
  • Baseline the directories the server normally accesses and alert on deviations.
  • Monitor environment variable configuration at process startup to confirm EXCEL_FILES_PATH is set.

How to Mitigate CVE-2026-85661

Immediate Actions Required

  • Set EXCEL_FILES_PATH to a dedicated, non-sensitive directory before starting the server in stdio mode.
  • Run excel-mcp-server under a low-privilege service account with access limited to the workbook directory.
  • Restrict which clients can reach the MCP stdio interface, and treat all MCP inputs as untrusted.
  • Track the project repository for a patched release addressing the path confinement gap.

Patch Information

No fixed version is identified in the CVE record at the time of publication. Monitor the GitHub project repository and GitHub issue #149 for remediation updates. Apply upstream fixes as soon as they are released.

Workarounds

  • Always define EXCEL_FILES_PATH and validate that the server refuses paths outside that base.
  • Deploy the server inside a container or chroot with only the workbook directory mounted.
  • Apply mandatory access controls such as AppArmor or SELinux profiles that restrict file access.
  • Disable stdio mode where feasible and expose the server only through interfaces with authenticated, path-validated access.
bash
# Configuration example: constrain excel-mcp-server to a dedicated directory
export EXCEL_FILES_PATH="/var/lib/excel-mcp/workbooks"
mkdir -p "$EXCEL_FILES_PATH"
chown excel-mcp:excel-mcp "$EXCEL_FILES_PATH"
chmod 750 "$EXCEL_FILES_PATH"
sudo -u excel-mcp excel-mcp-server --transport stdio

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.