CVE-2026-57441: MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

Published Sep 15, 2026
·
Updated

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and Windows filesystems, case variants of .git, .obsidian, or nodemodules pass both isAllowed() and isAllowedForListing() even though the operating system opens the restricted directory, and Windows trailing dots or spaces provide the same bypass. An attacker who influences a path selected by an AI agent can use the bypass in read, write, move, search, or listing operations to expose or modify sensitive repository and Obsidian metadata. Vault-root .. containment is not affected. This issue is fixed in version 0.11.4.

Affected Software

1 affected component
MCPVault MCPVault<0.11.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MCPVault to a version that resolves this vulnerability.

    Fixed in 0.11.4

Event History

Sep 15, 2026
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this bypass?

MCPVault versions before 0.11.4 are exposed when the vault is on a case-insensitive macOS or Windows filesystem. Windows systems are also affected by path segments with trailing dots or spaces.

2

What must an attacker be able to do to exploit it?

The attacker must be able to influence a path selected by an AI agent. They can use case variants of restricted directory names, or on Windows names with trailing dots or spaces, to bypass the PathFilter deny-list.

3

What operations can be abused after bypassing the filter?

The bypass applies to read, write, move, search, and directory-listing operations. It can expose or modify content in .git, .obsidian, or node_modules directories.

4

Does this allow traversal outside the vault root?

No. Vault-root .. containment is not affected by this issue.

5

What is the available remediation?

Upgrade MCPVault to version 0.11.4, which fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203