CVE-2026-57441
CVE-2026-57441 is a high-severity vulnerability with a CVSS 4.0 base score of 8.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-41.
Key facts
- Severity: High (CVSS 4.0 base score 8.4)
- EPSS exploit prediction: 0% (9th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-41
- Published:
- Last modified:
Description
MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and Windows filesystems, case variants of .git, .obsidian, or node_modules pass both isAllowed() and isAllowedForListing() even though the operating system opens the restricted directory, and Windows trailing dots or spaces provide the same bypass. An attacker who influences a path selected by an AI agent can use the bypass in read, write, move, search, or listing operations to expose or modify sensitive repository and Obsidian metadata. Vault-root .. containment is not affected. This issue is fixed in version 0.11.4.
Frequently asked questions
- What is CVE-2026-57441?
- MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and Windows filesystems, case variants of .git, .obsidian, or node_modules pass both isAllowed() and isAllowedForListing() even though the operating system opens the restricted directory, and Windows trailing dots or spaces provide the same bypass. An attacker who influences a path selected by an AI agent can use the bypass in read, write, move, search, or listing operations to expose or modify sensitive repository and Obsidian metadata. Vault-root .. containment is not affected. This issue is fixed in version 0.11.4.
- How severe is CVE-2026-57441?
- CVE-2026-57441 has a CVSS 4.0 base score of 8.4, rated high severity.
- Is CVE-2026-57441 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (9th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-57441?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-57441 published?
- CVE-2026-57441 was published on 2026-09-15 and last updated on 2026-09-30.
References
- https://github.com/bitbonsai/mcpvault/commit/0adb43901e1a08e85e14b42a8df2442fabc0b64a
- https://github.com/bitbonsai/mcpvault/commit/b9ea91a1c6d6adfec3e9e0483d9d79669e927fa8
- https://github.com/bitbonsai/mcpvault/security/advisories/GHSA-j99q-93c9-h869
Other CWE-41 vulnerabilities
- CVE-2026-85978 — Critical (CVSS 9.8): An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A…
- CVE-2025-24470 — High (CVSS 8.6): An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through…
- CVE-2026-5816 — High (CVSS 8.0): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before…
- CVE-2025-43298 — High (CVSS 7.8): A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in…
- CVE-2024-30073 — High (CVSS 7.8): Windows Security Zone Mapping Security Feature Bypass Vulnerability
- CVE-2023-36396 — High (CVSS 7.8): Windows Compressed Folder Remote Code Execution Vulnerability