Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j99q-93c9-h869 | MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence |
Tue, 15 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and Windows filesystems, case variants of .git, .obsidian, or node_modules pass both isAllowed() and isAllowedForListing() even though the operating system opens the restricted directory, and Windows trailing dots or spaces provide the same bypass. An attacker who influences a path selected by an AI agent can use the bypass in read, write, move, search, or listing operations to expose or modify sensitive repository and Obsidian metadata. Vault-root .. containment is not affected. This issue is fixed in version 0.11.4. | |
| Title | MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence | |
| Weaknesses | CWE-178 CWE-41 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T19:43:58.303Z
Reserved: 2026-06-24T13:21:20.729Z
Link: CVE-2026-57441
No data.
Status : Received
Published: 2026-09-15T18:17:25.467
Modified: 2026-09-15T18:17:25.467
Link: CVE-2026-57441
No data.
OpenCVE Enrichment
No data.

Github GHSA