MEDIUM
Deepractice
CVE published 2026-04-28
CVE-2026-7217
CVE-2026-7217 is an absolute path traversal vulnerability in Deepractice PromptX up to 2.4.0. The affected component is the Document File Handler, specifically the functions read_docx, read_xlsx, read_pptx, list_xlsx_sheets, and read_pdf in the file packages/mcp-office/src/index.ts. This vulnerability allows remote attackers to manipulate the path argument, potentially leading to unauthorized file access. [truncated]