Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mleitnercom

#29121of 57,624
9.4Total CVSS
Vulnerabilities · 1
PT-2026-95077
9.4
2026-09-17
Unknown · Obsidian-Web-Mcp · CVE-2026-54618
**Name of the Vulnerable Software and Affected Versions** Obsidian Web MCP versions prior to 0.2.0 **Description** An authentication bypass exists where the '/oauth/authorize' endpoint issues an authorization code without requiring login, consent, or a session check. Subsequently, the '/oauth/token' endpoint allows the exchange of this code for the static `VAULT MCP TOKEN` without client authentication. This enables an unauthenticated remote caller to access the '/mcp' endpoint and execute `vault read`, `vault write`, `vault search`, `vault list`, `vault move`, and `vault delete` operations across the entire vault. Additionally, the '/oauth/register' endpoint is unauthenticated and exposes the `VAULT OAUTH CLIENT SECRET`, providing a client credentials path. Proof Key for Code Exchange (PKCE), a security extension for OAuth 2.0, does not prevent this attacker-initiated flow. **Recommendations** Update to version 0.2.0.