PT-2026-96284 · Unknown · Notebooklm-Mcp
CVE-2026-61647
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NotebookLM MCP versions 1.6.0 through 2.0.2
Description
NotebookLM MCP contains a path traversal issue where attacker-controlled values in the
vault dir and slug prefix variables can cause Markdown and JSON files to be written outside the intended vault directory to any location writable by the server process. This is possible because the vault dir path was passed to path.resolve() and fs.mkdir() without containment checks, and the slug prefix was concatenated into filenames without sanitization. This issue is present in the POST /batch-to-vault endpoint and the batch to vault MCP tool. In scenarios involving prompt injection or multi-user environments, an attacker could plant files in sensitive locations such as autostart folders or shell startup files.Recommendations
Update to version 2.0.3 and set the
NOTEBOOKLM VAULT ROOT environment variable to enable vault containment.
As a temporary workaround, run the server using a dedicated unprivileged account restricted to the intended vault.
Limit the POST /batch-to-vault endpoint to localhost.
Validate vault dir values supplied by LLMs that process untrusted content.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Notebooklm-Mcp