What is CVE-2026-65695?
CVE-2026-65695 is a path traversal vulnerability in Office-Word-MCP-Server through version 1.1.11, exploitable via the "filename" argument in its document tools. Attackers can leverage this to read arbitrary .docx files outside the intended working directory, or to create and overwrite .docx files by supplying absolute paths. Users should update the server immediately and implement strict validation of file path inputs.
Azərbaycanca: CVE-2026-65695 Office-Word-MCP-Server-in 1.1.11 versiyasına qədər olan versiyalarında "filename" arqumenti vasitəsilə path traversal zəifliyi aşkarlanıb. Bu, təcavüzkara nəzərdə tutulan işçi qovluqdan kənarda yerləşən .docx fayllarını oxumağa və ya yaratmağa/üzerinə yazmağa imkan verir. İstifadəçilər dərhal serveri ən son versiyaya yeniləməli və fayl yolu girişlərini ciddi şəkildə doğrulamalıdırlar.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What actions can an attacker perform by exploiting CVE-2026-65695?
An attacker can leverage the "filename" argument to perform path traversal, reading .docx files outside the intended working directory, or creating and overwriting .docx files.
Which versions of Office-Word-MCP-Server are affected by CVE-2026-65695?
All versions up to and including 1.1.11 are affected by this path traversal vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.