CVE-2026-7212 Details
Description
A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notes_mcp.py. The manipulation of the argument root_dir/path leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
A path traversal vulnerability has been identified in Edvard Lindelof's Notes-MCP application, specifically in versions up to 0.1.4. The issue arises in the file 'notes_mcp.py', where the 'root_dir' argument is manipulated, allowing attackers to traverse directories. This vulnerability can be exploited remotely, and a public exploit is available. The project has been notified of this issue but has not yet responded.
It is recommended to update the 'notes_mcp.py' file to include path normalization and boundary checks before file operations. Additionally, destructive tools should be disabled in untrusted deployments until a fix is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 28, 2026CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/edvardlindelof/notes-mcp/ | [email protected] | ProductVendor |
| https://github.com/edvardlindelof/notes-mcp/issues/2 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://vuldb.com/submit/802084 | [email protected] | Technical Description |
| https://vuldb.com/vuln/359808 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/359808/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| edvardlindelof notes-mcp | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 28, 2026 | New CVE Received | [email protected] |
Volerion