Directory Access Bypass Vulnerability in MCPVault by Bitbonsai
CVE-2026-57441
8.4HIGH
What is CVE-2026-57441?
MCPVault, a lightweight server for secure file access in Obsidian vaults, has a critical vulnerability where restricted-directory patterns are processed in a case-sensitive manner. This issue, present before version 0.11.4, allows case variants of directories such as .git and .obsidian to bypass security checks on case-insensitive file systems like macOS and Windows. Consequently, an attacker could manipulate paths chosen by an AI agent to gain unauthorized access to read, write, move, search, or view sensitive information within repositories and Obsidian metadata. The vulnerability underscores the need for careful handling of path normalization to mitigate exposure risks.
Affected Version(s)
mcpvault < 0.11.4
