Please report vulnerabilities privately through GitHub security advisories, not in public issues. Include the version, the transport (stdio or Streamable HTTP), and steps or a proof of concept.
You can expect a first response within a week. Fixes are released as soon as they are ready, and reporters are credited in the advisory and the changelog unless they prefer otherwise.
Security fixes are made for the latest release.
The server acts on behalf of whoever can call its tools: the local MCP client in stdio mode, or anyone who can reach the HTTP endpoint. Its defences are:
- Files: only Excel files (
.xlsx,.xlsm,.xltx,.xltm), confined to the--allow-dirfolders when they are set (always in HTTP mode), after resolving symlinks. Existing files are only replaced when a tool is asked to overwrite them. - Formulas: every formula is tokenized and rejected if it uses a function that reaches the network, other programs or host information, a DDE link, or another workbook.
- Network: HTTP binds to localhost by default with DNS rebinding protection. A public
host requires
EXCEL_MCP_AUTH_TOKENunless--allow-unauthenticatedis passed for a deployment where a proxy handles authentication. - Resources: limits on file size and on the cells read or written per call.
- Macros: VBA code is parsed as text by the server's own [MS-OVBA] reader with size
limits, and is never run. Macros in
.xlsmfiles are kept intact but cannot be changed.
Out of scope: an assistant acting on instructions hidden in cell text (prompt injection)
is a risk of the client and model; the server marks cell contents as untrusted data but
cannot prevent it. Run the server with --read-only or a narrow --allow-dir when working
with untrusted workbooks.