Executive brief
Obsidian Web MCP is a remote server that manages access to Obsidian note vaults via OAuth. Versions before 0.2.0 allow any unauthenticated user who can reach the server to bypass login and consent checks, obtaining full read, write, delete, and move access to the entire vault without valid credentials. This effectively gives attackers complete control over all stored notes and data.
Technical details
The vulnerability is an OAuth authorization bypass in the /oauth/authorize endpoint, which issued authorization codes without requiring user login, consent, or session validation. The /oauth/token endpoint then exchanged these codes for a static VAULT_MCP_TOKEN without client authentication. An unauthenticated remote attacker with network access to the server can complete the OAuth flow and access MCP methods vault_read, vault_write, vault_search, vault_list, vault_move, and vault_delete. PKCE and client secrets provided no protection because the attacker controls the entire flow. Additionally, the /oauth/register endpoint exposed the configured VAULT_OAUTH_CLIENT_SECRET to any caller. Version 0.2.0 fixes this by requiring interactive login (username/password) before issuing authorization codes, mandating PKCE (S256), validating redirect_uri, binding to 127.0.0.1 by default, and implementing per-client secrets.
Affected products
- Obsidian Web MCP Obsidian Web MCP before 0.2.0
Timeline
- 2026-09-17: disclosed
- 2026-06-07: patched: Version 0.2.0 released with fix