GHSA-vc5j-42hh-j3mr

Suggest an improvement
Source
https://github.com/advisories/GHSA-vc5j-42hh-j3mr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vc5j-42hh-j3mr/GHSA-vc5j-42hh-j3mr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vc5j-42hh-j3mr
Aliases
  • CVE-2026-7212
Published
2026-04-28T03:31:29Z
Modified
2026-05-06T19:52:38.632111Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
notes-mcp has a Path Traversal issue
Details

A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notesmcp.py. The manipulation of the argument rootdir/path leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "github_reviewed_at": "2026-05-06T19:17:13Z",
    "github_reviewed": true,
    "severity": "MODERATE",
    "nvd_published_at": "2026-04-28T02:16:08Z",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

PyPI / notes-mcp

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.1.4

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vc5j-42hh-j3mr/GHSA-vc5j-42hh-j3mr.json"