VYPR

Obsidian Web MCP

by Obsidian

CVEs (1)

  • CVE-2026-54618CriSep 17, 2026
    risk 0.61cvss 9.4epss

    Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MCP_TOKEN without authenticating a client.…