Description
Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MCP_TOKEN without authenticating a client. An unauthenticated remote caller who can reach the intended tunnel deployment can therefore call /mcp and use vault_read, vault_write, vault_search, vault_list, vault_move, and vault_delete against the entire vault. Optional PKCE does not prevent an attacker-initiated flow, and unauthenticated /oauth/register also exposes a client_credentials path by returning the configured VAULT_OAUTH_CLIENT_SECRET. This issue is fixed in version 0.2.0.
Published: 2026-09-17
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Full vault compromise
Action: Immediate Patch
AI Analysis

Impact

Obsidian Web MCP allows an unauthenticated attacker to initiate an OAuth flow that issues an authorization code without prompting the user for login or consent. The resulting token can be exchanged for the static VAULT_MCP_TOKEN, granting the attacker unrestricted read, write, search, list, move, and delete capabilities on the entire vault. No session or authentication checks are performed during the flow, and optional PKCE does not mitigate the problem. The attacker can therefore hijack any deployed vault that is reachable through the MCP tunnel.

Affected Systems

The vulnerable application is the Obsidian Web MCP server developed by jimprosser. Any deployment running any pre‑0.2.0 release is affected because the security flaw exists in all versions prior to that point. The issue is fixed in version 0.2.0, which eliminates the unauthenticated OAuth issue and protects the vault from unauthorized access.

Risk and Exploitability

The CVSS score of 9.4 reflects the high severity of this vulnerability, and the EPSS score of less than 1% indicates that exploitation is currently unlikely but could occur under the right conditions. The vulnerability is not listed in CISA KEV, but it is remotely exploitable and does not require any user interaction. An attacker who can reach the MCP tunnel can both authenticate themselves and obtain the static token, giving full control over the vault.

Generated by OpenCVE AI on September 19, 2026 at 02:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Obsidian Web MCP to version 0.2.0 or later.
  • Restrict external access to the /oauth/authorize and /oauth/register endpoints, allowing only trusted networks to reach them.
  • Revoke the existing VAULT_MCP_TOKEN and regenerate secure credentials to invalidate any tokens that may have been issued during the vulnerable period.
  • Apply firewall or network segmentation rules to prevent unauthenticated traffic from reaching the MCP server until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Jimprosser
Jimprosser obsidian-web-mcp
Vendors & Products Jimprosser
Jimprosser obsidian-web-mcp

Thu, 17 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MCP_TOKEN without authenticating a client. An unauthenticated remote caller who can reach the intended tunnel deployment can therefore call /mcp and use vault_read, vault_write, vault_search, vault_list, vault_move, and vault_delete against the entire vault. Optional PKCE does not prevent an attacker-initiated flow, and unauthenticated /oauth/register also exposes a client_credentials path by returning the configured VAULT_OAUTH_CLIENT_SECRET. This issue is fixed in version 0.2.0.
Title Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user
Weaknesses CWE-306
CWE-522
CWE-601
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Jimprosser Obsidian-web-mcp
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:40:37.956Z

Reserved: 2026-06-15T20:07:02.184Z

Link: CVE-2026-54618

cve-icon Vulnrichment

Updated: 2026-09-24T20:40:15.984Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T20:16:51.823

Modified: 2026-09-30T17:32:07.107

Link: CVE-2026-54618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-522

    Insufficiently Protected Credentials

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')