{"id":"CVE-2025-71427","summary":"Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_image","details":"Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.","modified":"2026-10-03T11:30:21.339124694Z","published":"2026-10-01T22:53:04.500Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71427.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71427.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71427"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/office-powerpoint-mcp-server-through-2.0.7-path-traversal-via-save-presentation-and-manage-image"},{"type":"FIX","url":"https://github.com/GongRzhe/Office-PowerPoint-MCP-Server/pull/33"},{"type":"PACKAGE","url":"https://github.com/GongRzhe/Office-PowerPoint-MCP-Server"},{"type":"ARTICLE","url":"https://github.com/GongRzhe/Office-PowerPoint-MCP-Server/blob/3631ba2ec0c24504476f78bf74d329c9be11caaa/tools/presentation_tools.py#L127-L141"},{"type":"ARTICLE","url":"https://github.com/GongRzhe/Office-PowerPoint-MCP-Server/blob/3631ba2ec0c24504476f78bf74d329c9be11caaa/utils/presentation_utils.py#L61-L73"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gongrzhe/office-powerpoint-mcp-server","events":[{"introduced":"0"},{"fixed":"3631ba2ec0c24504476f78bf74d329c9be11caaa"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.0.7"},{"fixed":"2.0.7"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71427.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}