CVE-2026-57442: MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5,
Summary
MCPVault, a server that lets AI safely access files in an Obsidian vault (a note-taking app), had a security flaw before version 0.11.5 where its path filter (the code that blocks access to certain folders) only blocked top-level restricted folders like .git and node_modules. An attacker could bypass this by accessing these same folders when they were nested deeper in the directory structure, potentially exposing sensitive files, tokens (credentials used for authentication), or corrupting search indexes.
Solution / Mitigation
Update MCPVault to version 0.11.5 or later, where this issue is fixed.
Vulnerability Details
EPSS: 0.0%
September 15, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-57442
First tracked: September 15, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 92%