{"data":{"id":"e490d235-7857-40c7-86f7-90ba918f7191","title":"CVE-2025-71427: Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and…","summary":"CVE-2025-71427 affects Office-PowerPoint-MCP-Server through 2.0.7. A path traversal flaw lets MCP callers read and write files outside the working directory by supplying absolute paths or ../ sequences. An attacker can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-71427","publishedAt":"2026-10-01T23:16:46.613Z","cveId":"CVE-2025-71427","cweIds":["CWE-22"],"cvssScore":"6.8","cvssSeverity":"medium","severity":"medium","attackType":["prompt_injection","other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["Office-PowerPoint-MCP-Server","MCP"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00289,"epssCheckedAt":"2026-10-10T02:58:12.571Z","kevDateAdded":null,"advisoryAliases":["GHSA-xpvr-6r3p-gm34"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:02.062Z","patchAvailable":null,"disclosureDate":"2026-10-01T23:16:46.613Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0051"]}}