CVE-2026-61647 | roomi-fields notebooklm-mcp up to 2.0.2 Batch To Vault vault_dir/slug_prefix path traversal

SecurityVulns

A vulnerability has been found in roomi-fields notebooklm-mcp up to 2.0.2 and classified as critical. This impacts an unknown function of the component Batch To Vault. Performing a manipulation of the argument vault_dir/slug_prefix results in path traversal.

This vulnerability is known as CVE-2026-61647. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More