Description
MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and Windows filesystems, case variants of .git, .obsidian, or node_modules pass both isAllowed() and isAllowedForListing() even though the operating system opens the restricted directory, and Windows trailing dots or spaces provide the same bypass. An attacker who influences a path selected by an AI agent can use the bypass in read, write, move, search, or listing operations to expose or modify sensitive repository and Obsidian metadata. Vault-root .. containment is not affected. This issue is fixed in version 0.11.4.
Published: 2026-09-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality and Integrity Compromise
Action: Patch Immediately
AI Analysis

Impact

MCPVault is a lightweight server that allows AI agents to access a user’s Obsidian vault. Prior to version 0.11.4 the service’s PathFilter evaluated restricted‑directory patterns case‑sensitively and did not canonicalise filesystem segments. On case‑insensitive or dot/space‑equivalent filesystems such as macOS and Windows, paths that differ only by case or trailing dots/spaces could bypass the blocks for .git, .obsidian, or node_modules. This bypass enabled read, write, move, search, or listing operations on those sensitive directories, exposing or allowing manipulation of repository and vault metadata. Vault‑root containment remains intact, but the ability to alter critical files introduces both confidentiality exposure and integrity compromise.

Affected Systems

The affected product is MCPVault from bitbonsai. Versions of the Model Context Protocol server earlier than 0.11.4 are vulnerable, including any installation that exposes the MCPVault API to untrusted clients or internal AI agents.

Risk and Exploitability

With a CVSS score of 8.4 the vulnerability is classified as high severity, but the current EPSS score is below 1% and it is not listed in the CISA KEV catalog, implying a low present exploitation probability. Nevertheless, if an attacker can supply crafted file paths—e.g., by influencing an AI agent—the bypass can be leveraged to read or modify sensitive directories, exposing or altering critical metadata. The likely attack vector is through any operation that accepts user‑specified file paths, such as read, write, move, search, or listing.

Generated by OpenCVE AI on September 20, 2026 at 14:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MCPVault to version 0.11.4 or later.
  • Validate and reject any incoming paths that target .git, .obsidian, or node_modules directories.
  • Limit file‑system permissions for the MCPVault process so it cannot read or write critical directories under the vault root.
  • Monitor MCPVault logs for abnormal file access patterns and alert on violations.

Generated by OpenCVE AI on September 20, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j99q-93c9-h869 MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Bitbonsai
Bitbonsai mcpvault
Vendors & Products Bitbonsai
Bitbonsai mcpvault

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and Windows filesystems, case variants of .git, .obsidian, or node_modules pass both isAllowed() and isAllowedForListing() even though the operating system opens the restricted directory, and Windows trailing dots or spaces provide the same bypass. An attacker who influences a path selected by an AI agent can use the bypass in read, write, move, search, or listing operations to expose or modify sensitive repository and Obsidian metadata. Vault-root .. containment is not affected. This issue is fixed in version 0.11.4.
Title MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
Weaknesses CWE-178
CWE-41
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Bitbonsai Mcpvault
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:43:58.303Z

Reserved: 2026-06-24T13:21:20.729Z

Link: CVE-2026-57441

cve-icon Vulnrichment

Updated: 2026-09-15T18:57:32.544Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:25.467

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-57441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity

  • CWE-41

    Improper Resolution of Path Equivalence