CVE-2026-82111 | iswalle getnote-mcp up to 1.5.0 upload_image src/index.ts fs.readFileSync image_path path traversal (Issue 10)

SecurityVulns

A vulnerability was found in iswalle getnote-mcp up to 1.5.0. It has been rated as problematic. The affected element is the function fs.readFileSync of the file src/index.ts of the component upload_image. Performing a manipulation of the argument image_path results in path traversal.

This vulnerability is identified as CVE-2026-82111. The attack can be initiated remotely. Additionally, an exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More