Impact
MCPVault is a lightweight server that allows AI agents to access a user’s Obsidian vault. Prior to version 0.11.4 the service’s PathFilter evaluated restricted‑directory patterns case‑sensitively and did not canonicalise filesystem segments. On case‑insensitive or dot/space‑equivalent filesystems such as macOS and Windows, paths that differ only by case or trailing dots/spaces could bypass the blocks for .git, .obsidian, or node_modules. This bypass enabled read, write, move, search, or listing operations on those sensitive directories, exposing or allowing manipulation of repository and vault metadata. Vault‑root containment remains intact, but the ability to alter critical files introduces both confidentiality exposure and integrity compromise.
Affected Systems
The affected product is MCPVault from bitbonsai. Versions of the Model Context Protocol server earlier than 0.11.4 are vulnerable, including any installation that exposes the MCPVault API to untrusted clients or internal AI agents.
Risk and Exploitability
With a CVSS score of 8.4 the vulnerability is classified as high severity, but the current EPSS score is below 1% and it is not listed in the CISA KEV catalog, implying a low present exploitation probability. Nevertheless, if an attacker can supply crafted file paths—e.g., by influencing an AI agent—the bypass can be leveraged to read or modify sensitive directories, exposing or altering critical metadata. The likely attack vector is through any operation that accepts user‑specified file paths, such as read, write, move, search, or listing.
OpenCVE Enrichment
Github GHSA