Impact
Obsidian Web MCP allows an unauthenticated attacker to initiate an OAuth flow that issues an authorization code without prompting the user for login or consent. The resulting token can be exchanged for the static VAULT_MCP_TOKEN, granting the attacker unrestricted read, write, search, list, move, and delete capabilities on the entire vault. No session or authentication checks are performed during the flow, and optional PKCE does not mitigate the problem. The attacker can therefore hijack any deployed vault that is reachable through the MCP tunnel.
Affected Systems
The vulnerable application is the Obsidian Web MCP server developed by jimprosser. Any deployment running any pre‑0.2.0 release is affected because the security flaw exists in all versions prior to that point. The issue is fixed in version 0.2.0, which eliminates the unauthenticated OAuth issue and protects the vault from unauthorized access.
Risk and Exploitability
The CVSS score of 9.4 reflects the high severity of this vulnerability, and the EPSS score of less than 1% indicates that exploitation is currently unlikely but could occur under the right conditions. The vulnerability is not listed in CISA KEV, but it is remotely exploitable and does not require any user interaction. An attacker who can reach the MCP tunnel can both authenticate themselves and obtain the static token, giving full control over the vault.
OpenCVE Enrichment