CVE-2026-82111

Source
https://cve.org/CVERecord?id=CVE-2026-82111
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82111.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82111
Published
2026-08-28T11:00:11.287Z
Modified
2026-08-30T03:48:22.095386231Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
iswalle getnote-mcp upload_image index.ts fs.readFileSync path traversal
Details

A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of the file src/index.ts of the component uploadimage. Performing a manipulation of the argument imagepath results in path traversal. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 1.5.1 is sufficient to fix this issue. The patch is named 7f9a215e03575c650d38c8f87fc6d8d363fed80d. Upgrading the affected component is advised.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82111.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.0"
                },
                {
                    "last_affected": "1.0"
                },
                {
                    "introduced": "1.1"
                },
                {
                    "last_affected": "1.1"
                },
                {
                    "introduced": "1.2"
                },
                {
                    "last_affected": "1.2"
                },
                {
                    "introduced": "1.3"
                },
                {
                    "last_affected": "1.3"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/iswalle/getnote-mcp

Affected ranges

Type
GIT
Repo
https://github.com/iswalle/getnote-mcp
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "1.4"
        },
        {
            "last_affected": "1.4"
        },
        {
            "introduced": "1.5.0"
        },
        {
            "last_affected": "1.5.0"
        }
    ]
}

Affected versions

1.*
1.4
1.5.0
v1.*
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.4.9
v1.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82111.json"