Description
MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules path segments do not match the restriction and pass both isAllowed() and isAllowedForListing(). An attacker who influences a path selected by an AI agent can traverse nested repository or Obsidian metadata, read remote URLs or embedded tokens, or cause nested node_modules content to pollute the listAllTags index. This issue is fixed in version 0.11.5.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Read via Path Traversal
Action: Immediate Patch
AI Analysis

Impact

PathFilter in MCPVault before version 0.11.5 uses a root-anchored deny-list, so nested .git, .obsidian, and node_modules segments are not matched and pass both isAllowed() and isAllowedForListing(). An attacker who can influence the path chosen by an AI agent can traverse into nested repositories or Obsidian metadata, read remote URLs or embedded tokens, or cause nested node_modules content to pollute the listAllTags index. The flaw allows disclosure of sensitive files and data, and also introduces the risk of index contamination, and is classified as CWE‑22 and CWE‑538.

Affected Systems

The affected product is MCPVault from bitbonsai. All versions before 0.11.5 are vulnerable; the issue persists for any installation that allows path selection by an external agent, such as an AI assistant, directly or indirectly.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate risk. The EPSS score is <1%, indicating a low probability of exploitation, but exploitation remains possible in environments where an AI agent or script can influence the file path. At present the vulnerability is not cataloged in CISA KEV, and no public exploits have been reported. The risk is therefore moderate, with potential impact limited to environments that expose the vault to uncontrolled path inputs.

Generated by OpenCVE AI on September 20, 2026 at 14:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MCPVault to version 0.11.5 or later to apply the PathFilter fix.
  • Configure the application to add explicit deny rules for nested .git, .obsidian, and node_modules directories, or enforce ACL restrictions to prevent traversal.
  • Restrict any AI agents or scripts that can influence file path selection to use only validated, whitelisted paths within the vault root.

Generated by OpenCVE AI on September 20, 2026 at 14:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9c83-rr99-vfwj MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Bitbonsai
Bitbonsai mcpvault
Vendors & Products Bitbonsai
Bitbonsai mcpvault

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules path segments do not match the restriction and pass both isAllowed() and isAllowedForListing(). An attacker who influences a path selected by an AI agent can traverse nested repository or Obsidian metadata, read remote URLs or embedded tokens, or cause nested node_modules content to pollute the listAllTags index. This issue is fixed in version 0.11.5.
Title MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
Weaknesses CWE-22
CWE-538
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Bitbonsai Mcpvault
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T14:01:51.831Z

Reserved: 2026-06-24T13:21:20.729Z

Link: CVE-2026-57442

cve-icon Vulnrichment

Updated: 2026-09-16T14:01:25.875Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:25.613

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-57442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-538

    Insertion of Sensitive Information into Externally-Accessible File or Directory