{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aroomi-fieldsnotebooklm-mcp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:roomi-fields:notebooklm-mcp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-61647"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["notebooklm-mcp (\u003e= 1.6.0, \u003c 2.0.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["roomi-fields"],"content_html":"\u003cp\u003eA path traversal vulnerability exists in the @roomi-fields/notebooklm-mcp package, affecting versions 1.6.0 through 2.0.2. The vulnerability stems from improper sanitization of the \u003ccode\u003evault_dir\u003c/code\u003e and \u003ccode\u003eslug_prefix\u003c/code\u003e parameters within the \u003ccode\u003evault.batch\u003c/code\u003e MCP tool and the corresponding \u003ccode\u003e/batch-to-vault\u003c/code\u003e HTTP endpoint. The application directly utilizes these parameters in file system operations using \u003ccode\u003epath.resolve()\u003c/code\u003e and \u003ccode\u003efs.mkdir()\u003c/code\u003e without enforcing boundary checks. An attacker or a compromised LLM driving the MCP interface can supply crafted path inputs containing directory traversal sequences (e.g., \u003ccode\u003e..\u003c/code\u003e) or absolute paths to write markdown and JSON files into sensitive directories on the host filesystem that the server process has permissions to access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to write files anywhere the server process has write access. While the files are inert content (markdown/JSON), this vulnerability poses a significant risk in multi-user environments or when the MCP server is integrated with LLMs that ingest untrusted user content (e.g., via prompt injection). Attackers could potentially plant files in autostart folders or shell configuration files, leading to downstream command execution or system persistence.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade @roomi-fields/notebooklm-mcp to version 2.0.3 or later immediately.\u003c/li\u003e\n\u003cli\u003eFollowing the upgrade, enforce directory containment by configuring the \u003ccode\u003eNOTEBOOKLM_VAULT_ROOT\u003c/code\u003e environment variable to a restricted directory path.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, restrict the exposure of the HTTP \u003ccode\u003e/batch-to-vault\u003c/code\u003e endpoint to local loopback interfaces only.\u003c/li\u003e\n\u003cli\u003eEnsure the service runs under a dedicated, unprivileged service account with write permissions restricted strictly to the intended vault location.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-22T19:53:56Z","date_published":"2026-09-22T19:53:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-notebooklm-mcp-traversal/","summary":"The @roomi-fields/notebooklm-mcp package is vulnerable to arbitrary file write via path traversal in the vault_batch tool and /batch-to-vault endpoint, allowing attackers to plant malicious files in unauthorized directories.","title":"Path Traversal Vulnerability in notebooklm-mcp","url":"https://feed.craftedsignal.io/briefs/2026-09-notebooklm-mcp-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:roomi-Fields:notebooklm-Mcp:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}