MediumVulnerability
CVE-2025-71427: Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2025-71427
- Published
- Record updated
Summary
CVE-2025-71427 affects Office-PowerPoint-MCP-Server through 2.0.7. A path traversal flaw lets MCP callers read and write files outside the working directory by supplying absolute paths or ../ sequences. An attacker can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database