Path Traversal Vulnerability in bazylhorsey obsidian-mcp-server
CVE-2026-19331
4.8MEDIUM
What is CVE-2026-19331?
A path traversal vulnerability has been identified in the bazylhorsey obsidian-mcp-server, particularly within the readCanvas/writeCanvas functions located in src/services/CanvasService.ts. This vulnerability enables an attacker to manipulate file paths, potentially gaining access to unauthorized files. The issue requires local access for exploitation. Although the project maintainers were notified of the vulnerability through an early issue report, no response has been documented. It is critical for users of this version to evaluate their risk and consider implementing security measures to mitigate potential exploitation.
Affected Version(s)
obsidian-mcp-server 1.0.0
