Medium severityNVD Advisory· Published Jun 18, 2026· Updated Jul 20, 2026
MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
CVE-2026-57441
Description
On case-insensitive filesystems (macOS, Windows), PathFilter compiled its deny-list patterns case-sensitively and matched the path verbatim, so names like .Git/config, .GIT/config, or .oBsIdIaN/secrets.md slipped past the .git/.obsidian/node_modules restriction while the OS opened the real file. On Windows, trailing dots/spaces (.git./config, .git /config) bypassed it the same way. Affects both isAllowed (read/write/move/search) and isAllowedForListing. Vault-root .. containment is NOT affected. Fixed in 0.11.4 by case-insensitive matching plus per-segment canonicalization before the deny-list check. Reported privately by novice-22.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@bitbonsai/mcpvaultnpm | < 0.11.4 | 0.11.4 |
Affected products
1- Range: <0.11.4
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.