This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
MCP Developer Tools
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai
automation
excel
llm
mcp
mcp-server
+4 more
sse
stdio
streamable-http
toolcalling
Affected surfaces
rce_ssrf
Summary
AI summaryFix path traversal vulnerability in SSE/streamable-http transports
Full changelog
Security
- Fix path traversal vulnerability in SSE/streamable-http transports
- Reported by @hits313
What's Changed
- feat: Add tool annotations for improved LLM tool understanding by @bryankthompson in https://github.com/haris-musa/excel-mcp-server/pull/110
- feat: Add MCPB bundle for Claude Desktop installation by @bryankthompson in https://github.com/haris-musa/excel-mcp-server/pull/112
New Contributors
- @bryankthompson made their first contribution in https://github.com/haris-musa/excel-mcp-server/pull/110
Full Changelog: https://github.com/haris-musa/excel-mcp-server/compare/v0.1.7...v0.1.8
Security Fixes
- Fix path traversal vulnerability in SSE/streamable-http transports (reported by @hits313)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About haris-musa/excel-mcp-server
An Excel manipulation server providing workbook creation, data operations, formatting, and advanced features (charts, pivot tables, formulae).
Related context
Beta — feedback welcome: [email protected]