CVE-2026-61647 | roomi-fields notebooklm-mcp up to 2.0.2 Batch To Vault vault_dir/slug_prefix path traversal
A vulnerability has been found in roomi-fields notebooklm-mcp up to 2.0.2 and classified as critical. This impacts an unknown function of the component Batch To Vault. Performing a manipulation of the argument vault_dir/slug_prefix results in path traversal.
This vulnerability is known as CVE-2026-61647. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.VulDB Recent EntriesRead More