Executive brief
A vulnerability in the Obsidian Local REST API plugin allows an authorized user or malicious application to access files outside of the designated Obsidian vault. By using specially formatted web addresses, an attacker can read, modify, or delete sensitive files on the host computer, such as SSH keys or browser data. This poses a significant risk in environments where AI agents or other automated tools are granted access to the API.
Technical details
A path traversal vulnerability exists in the `/vault/{path}` endpoints (GET, PUT, PATCH, POST, DELETE) of the obsidian-local-rest-api plugin. The root cause is that the application performs `decodeURIComponent` on the request path after the Express framework has already completed routing and normalization. While literal `../` sequences are blocked by Express, URL-encoded sequences like `%2F` or `%2e%2e` bypass these checks and are subsequently decoded into directory traversal characters within the request handler. Because the resulting path is passed to the Obsidian vault adapter without a confinement check (such as `path.resolve` against a synthetic root), an authenticated attacker can escape the vault directory to access the entire filesystem with the privileges of the Obsidian process. This is resolved in version 4.1.3.
Affected products
- coddingtonbear obsidian-local-rest-api < 4.1.3
Timeline
- 2026-06-04: disclosed: Initial disclosure to vendor
- 2026-06-04: patched: Version 4.1.3 released
- 2026-07-15: advisory: GitHub Advisory published
References
- https://api.github.com/users/AgenticWizard
- https://github.com/AgenticWizard
- https://api.github.com/users/AgenticWizard/gists%7B/gist_id%7D
- https://api.github.com/users/AgenticWizard/repos
- https://avatars.githubusercontent.com/u/268084991?v=4
- https://api.github.com/users/AgenticWizard/events%7B/privacy%7D