Sceawere
Vulnerability Detail
CVE-2025-71427UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Office-PowerPoint-MCP-Server Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 1d ago
- Vendor
- GongRzhe
- Product
- Office-PowerPoint-MCP-Server
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-01T23:16:46.613Z",
"pubdate": "2026-10-01T23:16:46.613Z",
"executiveSummary": "The Office-PowerPoint-MCP-Server, in versions through 2.0.7, is susceptible to a critical path traversal vulnerability. This security flaw originates from improper input validation when handling file paths within the MCP (Model Context Protocol) interface. An attacker can manipulate file operations to read from or write to arbitrary locations on the host filesystem that the server process has permissions to access.\nThe vulnerability is primarily triggered via AI agent interaction. By injecting malicious prompts, an attacker can coerce the AI agent into executing file operations using manipulated, absolute, or relative paths (such as ../ sequences). This allows the attacker to bypass directory restrictions, leading to potential data exfiltration, system configuration modification, or the overwriting of critical server-writable files.\nBecause the server interfaces with AI agents, the attack vector is amplified by the trust the agent places in the user's instructions. The vulnerability poses a significant risk as it grants an attacker the ability to interact with the underlying host OS through the server's file management functions, namely save_presentation, open_presentation, and manage_image. There are no authentication requirements mentioned, implying that any entity capable of sending commands to the MCP server can initiate the exploit sequence.",
"technicalDetails": "The vulnerability resides in the core file handling logic of the Office-PowerPoint-MCP-Server versions 2.0.7 and earlier. The root cause is the insufficient sanitization of path parameters supplied to internal API functions. Specifically, the server fails to enforce chroot or path-normalization constraints, allowing inputs containing directory traversal characters (e.g., '..') or absolute filesystem paths to be processed as legitimate local file references.\nThe attack flow leverages the integration between the MCP server and an AI agent. An attacker provides a crafted prompt designed to induce the AI agent to utilize specific file-related tools. For instance, an attacker might instruct the agent to use the 'save_presentation' function with an output_path parameter set to a sensitive system file, such as '/home/user/.ssh/authorized_keys' or other configuration files writable by the service account. Similarly, the 'open_presentation' and 'manage_image' functions can be exploited to read sensitive files from the server, effectively turning the server into a proxy for local file disclosure.\nWhen the MCP server receives a request from the AI agent containing a malicious path, it passes this path directly to underlying filesystem APIs. Since the software fails to validate that the resolved path resides within the intended working directory, the operating system executes the requested operation at the path provided by the attacker. If the server process runs with elevated privileges or has write access to critical application directories, the impact is severe.\nExploitation does not require prior authentication to the server, as the MCP interface is intended to be communicative with AI agents; however, the successful injection relies on the agent's willingness to follow the user's malicious instructions. The post-exploitation impact includes unauthorized reading of source code, configuration data, or private keys, as well as the ability to overwrite or corrupt files, leading to potential remote code execution or complete service denial. The vulnerability persists across all deployment environments where the server is exposed to untrusted MCP callers."
}