Medium severityGHSA Advisory· Published Sep 15, 2026· Updated Sep 16, 2026
CVE-2026-57442
CVE-2026-57442
Description
MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules path segments do not match the restriction and pass both isAllowed() and isAllowedForListing(). An attacker who influences a path selected by an AI agent can traverse nested repository or Obsidian metadata, read remote URLs or embedded tokens, or cause nested node_modules content to pollute the listAllTags index. This issue is fixed in version 0.11.5.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@bitbonsai/mcpvaultnpm | < 0.11.5 | 0.11.5 |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-9c83-rr99-vfwjghsaADVISORY
- github.com/bitbonsai/mcpvault/security/advisories/GHSA-9c83-rr99-vfwjnvdWEB
- github.com/bitbonsai/mcpvault/commit/0adb43901e1a08e85e14b42a8df2442fabc0b64anvd
- github.com/bitbonsai/mcpvault/commit/8795716b90d1c4090a82a58647e030763513f17envd
- github.com/bitbonsai/mcpvault/issues/128nvd
News mentions
0No linked articles in our index yet.