Directory Access Bypass Vulnerability in MCPVault by Bitbonsai
CVE-2026-57441

8.4HIGH

Key Information:

Vendor

Bitbonsai

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-57441?

MCPVault, a lightweight server for secure file access in Obsidian vaults, has a critical vulnerability where restricted-directory patterns are processed in a case-sensitive manner. This issue, present before version 0.11.4, allows case variants of directories such as .git and .obsidian to bypass security checks on case-insensitive file systems like macOS and Windows. Consequently, an attacker could manipulate paths chosen by an AI agent to gain unauthorized access to read, write, move, search, or view sensitive information within repositories and Obsidian metadata. The vulnerability underscores the need for careful handling of path normalization to mitigate exposure risks.

Affected Version(s)

mcpvault < 0.11.4

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.