CVE-2026-65695 | GongRzhe Office-Word-MCP-Server up to 1.1.11 Document Tools check_file_writeable/ensure_docx_extension filename path traversal
A vulnerability identified as critical has been detected in GongRzhe Office-Word-MCP-Server up to 1.1.11. Affected is the function check_file_writeable/ensure_docx_extension of the component Document Tools. Performing a manipulation of the argument filename results in path traversal. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2026-65695. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More