OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-61647

HIGH · CVSS 7.1 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Versions 1.6.0 through 2.0.2 of NotebookLM MCP are vulnerable to a path traversal flaw in the `POST /batch-to-vault` endpoint, allowing attackers to write files outside the designated vault directory due to insufficient input validation. This vulnerability poses a high risk as it can lead to unauthorized file access and potential system compromise. Organizations using affected versions should prioritize upgrading to version 2.0.3 or implement strict access controls and input validation measures to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61647
Severity
HIGH
CVSS
7.1
EPSS
0.32%

Original NVD Description

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-to-vault` endpoint, also exposed through the `batch_to_vault` MCP tool beginning in version 1.7.0, because attacker-controlled `vault_dir` and `slug_prefix` values can cause Markdown and JSON files to be written outside the intended vault directory to any location writable by the server process. Version 2.0.3 sanitizes `slug_prefix` and supports vault containment when `NOTEBOOKLM_VAULT_ROOT` is configured; containment is not enabled if that variable is unset. Users unable to upgrade should run the server as a dedicated unprivileged account restricted to the intended vault, keep the HTTP endpoint limited to localhost, and validate `vault_dir` values supplied by LLMs processing untrusted content.