Junglewise Threat Intelligence

CVE-2026-7212: edvardlindelof notes-mcp path traversal in notes_mcp.py

CVE-2026-7212 · Severity: high · CVSS 7.3 · Published 2026-04-28

Vendors: PyPI.

Executive brief

notes-mcp is a tool used to allow AI chatbots to manage and organize text notes on a computer. A security flaw allows a remote attacker to bypass the intended storage folder and access any file on the host system. This could result in the theft of sensitive data, the modification of system files, or the deletion of important information.

Technical details

A path traversal vulnerability (CWE-22) exists in notes_mcp.py due to improper validation of user-supplied paths. The application uses simple path concatenation (root_dir / path) for file operations including read, write, mkdir, rm, and rmdir without resolving the resulting path or verifying it remains within the 'root_dir' boundary. A remote attacker can use '../' sequences in the 'path' argument to escape the sandbox and perform arbitrary file system operations with the permissions of the service account. As of the advisory date, no official patch has been released.

Affected products

  • edvardlindelof notes-mcp up to 0.1.4

Timeline

  • 2026-04-10: disclosed: Vulnerability reported to vendor via GitHub issue
  • 2026-04-28: advisory: NVD publication date

References