---
id: CVE-2026-7212
aliases:
  - GHSA-vc5j-42hh-j3mr
  - PYSEC-2026-2684
title: notes-mcp has a Path Traversal issue
summary: notes-mcp has a Path Traversal issue
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
vendor: notes-mcp
product: notes-mcp
ecosystem: pip
affected:
  - notes-mcp <= 0.1.4
published: '2026-04-28'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-vc5j-42hh-j3mr'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7212'
  - url: 'https://github.com/edvardlindelof/notes-mcp/issues/2'
  - url: 'https://github.com/edvardlindelof/notes-mcp'
  - url: 'https://vuldb.com/submit/802084'
  - url: 'https://vuldb.com/vuln/359808'
  - url: 'https://vuldb.com/vuln/359808/cti'
tags:
  - osv
  - pip
epss: 0.0041
epssPercentile: 0.34977
ingestedAt: '2026-07-13T18:58:03.451Z'
---

## Overview

A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notes_mcp.py. The manipulation of the argument root_dir/path leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

## Affected packages

- `notes-mcp <= 0.1.4`

## Remediation

Refer to the advisory for the patched release.
