


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notes_mcp.py. The manipulation …
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 21:20:20
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A path traversal vulnerability (CVE-2026-7212) has been discovered in edvardlindelof notes-mcp versions up to 0.1.4. The vulnerability affects an unknown function in the notes_mcp.py file through manipulation of the root_dir/path argument. The attack can be executed remotely and the exploit has been publicly disclosed. The vulnerability allows attackers to traverse file system paths outside intended directories. The project maintainer was notified through an issue report but has not responded yet.
Technical details
Mitigation steps:
Affected products:
edvardlindelof notes-mcp
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7212
https://github.com/edvardlindelof/notes-mcp/
https://github.com/edvardlindelof/notes-mcp/issues/2
https://vuldb.com/submit/802084
https://vuldb.com/vuln/359808
https://vuldb.com/vuln/359808/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
