Executive brief
obsidian-local-rest-api is a REST API plugin for Obsidian note-taking software that enables programmatic access to vault content. An authenticated attacker can exploit URL-encoded path traversal (%2F sequences) in the /vault/{path} endpoints to read, write, or delete arbitrary files on the host system with the Obsidian process's privileges, potentially exposing SSH keys, browser profiles, and other sensitive data. This risk is amplified when the API is used as an MCP server for AI agents, where a malicious prompt or agent could escalate access from vault-only to arbitrary filesystem operations.
Technical details
The vulnerability is a path traversal (CWE-22) in the request handler for /vault/{path} endpoints (GET, PUT, PATCH, POST, DELETE). The root cause lies in src/requestHandler.ts: after Express routing normalizes and rejects literal ../ sequences, the handler calls decodeURIComponent() on the request path, which converts URL-encoded sequences like ..%2F and %2e%2e into literal ../ and .., escaping the vault root. An authenticated client (API key required) can craft requests like /vault/..%2F..%2F..%2Fetc%2Fpasswd to access files outside the vault. The fix exists in the codebase's vaultMove handler (using posix.resolve with startsWith validation) but is missing from the other five handlers. Patches are available in version 4.1.3 and later.
Affected products
- coddingtonbear obsidian-local-rest-api < 4.1.3
Timeline
- 2026-07-15: disclosed
- 2026-07-15: patched: version 4.1.3 released