@roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory (CVE-2026-61647) | HOL Guard CVE