CVE-2026-19331 | bazylhorsey obsidian-mcp-server 1.0.0 CanvasService.ts readCanvas/writeCanvas path traversal
A vulnerability categorized as critical has been discovered in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-19331. An attack has to be approached locally. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More