Impact
PathFilter in MCPVault before version 0.11.5 uses a root-anchored deny-list, so nested .git, .obsidian, and node_modules segments are not matched and pass both isAllowed() and isAllowedForListing(). An attacker who can influence the path chosen by an AI agent can traverse into nested repositories or Obsidian metadata, read remote URLs or embedded tokens, or cause nested node_modules content to pollute the listAllTags index. The flaw allows disclosure of sensitive files and data, and also introduces the risk of index contamination, and is classified as CWE‑22 and CWE‑538.
Affected Systems
The affected product is MCPVault from bitbonsai. All versions before 0.11.5 are vulnerable; the issue persists for any installation that allows path selection by an external agent, such as an AI assistant, directly or indirectly.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk. The EPSS score is <1%, indicating a low probability of exploitation, but exploitation remains possible in environments where an AI agent or script can influence the file path. At present the vulnerability is not cataloged in CISA KEV, and no public exploits have been reported. The risk is therefore moderate, with potential impact limited to environments that expose the vault to uncontrolled path inputs.
OpenCVE Enrichment
Github GHSA