Executive brief
GetNote MCP is a note-taking component used within model context protocol integrations. A path traversal vulnerability in the image upload feature allows attackers to read arbitrary files from the server by manipulating the image path parameter, potentially exposing sensitive configuration files, credentials, or other data stored on the system.
Technical details
The vulnerability exists in the fs.readFileSync function of src/index.ts within the upload_image component. By manipulating the image_path argument, an attacker can traverse the file system directory structure (e.g., using ../ sequences) to read files outside the intended upload directory. This is a classic path traversal flaw requiring no authentication. The attack is network-accessible and the exploit has been made public. Upgrading to version 1.5.1 or later (commit 7f9a215e03575c650d38c8f87fc6d8d363fed80d) resolves the issue.
Affected products
- iswalle getnote-mcp up to 1.5.0
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Version 1.5.1 released with fix (commit 7f9a215e03575c650d38c8f87fc6d8d363fed80d)