Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 09 Aug 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack has to be approached locally. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | bazylhorsey obsidian-mcp-server CanvasService.ts writeCanvas path traversal | |
| First Time appeared |
Bazylhorsey
Bazylhorsey obsidian-mcp-server |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:bazylhorsey:obsidian-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bazylhorsey
Bazylhorsey obsidian-mcp-server |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-09T04:15:10.641Z
Reserved: 2026-08-08T09:30:23.512Z
Link: CVE-2026-19331
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-09T05:30:16Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')