PT-2026-96284 · Unknown · Notebooklm-Mcp

CVE-2026-61647

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NotebookLM MCP versions 1.6.0 through 2.0.2
Description NotebookLM MCP contains a path traversal issue where attacker-controlled values in the vault dir and slug prefix variables can cause Markdown and JSON files to be written outside the intended vault directory to any location writable by the server process. This is possible because the vault dir path was passed to path.resolve() and fs.mkdir() without containment checks, and the slug prefix was concatenated into filenames without sanitization. This issue is present in the POST /batch-to-vault endpoint and the batch to vault MCP tool. In scenarios involving prompt injection or multi-user environments, an attacker could plant files in sensitive locations such as autostart folders or shell startup files.
Recommendations Update to version 2.0.3 and set the NOTEBOOKLM VAULT ROOT environment variable to enable vault containment. As a temporary workaround, run the server using a dedicated unprivileged account restricted to the intended vault. Limit the POST /batch-to-vault endpoint to localhost. Validate vault dir values supplied by LLMs that process untrusted content.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61647
GHSA-JJHP-8CRJ-MPPQ

Affected Products

Notebooklm-Mcp