Path Traversal Vulnerability in edvardlindelof notes-mcp Software
CVE-2026-7212
Key Information:
- Vendor
Edvardlindelof
- Status
- Vendor
- CVE Published:
- 28 April 2026
Badges
What is CVE-2026-7212?
A security vulnerability has been identified in the notes-mcp application developed by edvardlindelof, specifically affecting version 0.1.4. The flaw resides in an unknown function within the notes_mcp.py file, where improper validation of the root_dir/path argument enables unauthorized access to the file system. This situation allows attackers to conduct path traversal attacks, potentially leading to the exposure of sensitive files on the server. The vulnerability can be exploited remotely, and although the issue has been publicly disclosed, the vendor has yet to address the report.
Affected Version(s)
notes-mcp 0.1.0
notes-mcp 0.1.1
notes-mcp 0.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
