Path Traversal Vulnerability in iswalle Getnote-MCP Component
CVE-2026-82111
Key Information:
- Vendor
Iswalle
- Status
- Vendor
- CVE Published:
- 28 August 2026
Badges
What is CVE-2026-82111?
A path traversal vulnerability exists in the upload_image component of iswalle Getnote-MCP, affecting versions up to 1.5.0. This issue arises from improper handling of the argument image_path in the fs.readFileSync function found in src/index.ts. An attacker could exploit this vulnerability remotely, allowing unauthorized access to the file system. It is crucial to upgrade to version 1.5.1 or later, which includes a patch to address this critical security flaw. Timely application of the security update is recommended to prevent potential exploitation.
Affected Version(s)
getnote-mcp 1.0
getnote-mcp 1.1
getnote-mcp 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
