CVE 6.9 MEDIUM

UsamaK98 python-notebook-mcp server.py add_cell path traversal_CVE-2026-7810

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_notebook/edit_cell/add_cell of the file server.py. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Basic Information

ID CVE-2026-7810
Source VulDB
Published May 5, 2026 at 03:45

Affected Product

Vendor UsamaK98
Product python-notebook-mcp
Version a05a232815809a7e425b5fa7be26e0d4369894c2
Affected Versions UsamaK98 python-notebook-mcp a05a232815809a7e425b5fa7be26e0d4369894c2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.