CVE-2025-71427
Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_image
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.
| CWE | CWE-22 |
| Vendor | gongrzhe |
| Product | office-powerpoint-mcp-server |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for gongrzhe office-powerpoint-mcp-server
Be the first to know when new medium vulnerabilities affecting gongrzhe office-powerpoint-mcp-server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
GongRzhe / Office-PowerPoint-MCP-Server
0 โค 2.0.7
References
github.com: https://github.com/GongRzhe/Office-PowerPoint-MCP-Server/pull/33 github.com: https://github.com/GongRzhe/Office-PowerPoint-MCP-Server/blob/3631ba2ec0c24504476f78bf74d329c9be11caaa/utils/presentation_utils.py#L61-L73 github.com: https://github.com/GongRzhe/Office-PowerPoint-MCP-Server/blob/3631ba2ec0c24504476f78bf74d329c9be11caaa/tools/presentation_tools.py#L127-L141 github.com: https://github.com/GongRzhe/Office-PowerPoint-MCP-Server vulncheck.com: https://www.vulncheck.com/advisories/office-powerpoint-mcp-server-through-2.0.7-path-traversal-via-save-presentation-and-manage-image
Credits
Sonali Tyagi