What is CVE-2026-19331?
A path traversal vulnerability in bazylhorsey obsidian-mcp-server 1.0.0 affects the `readCanvas`/`writeCanvas` functions in `src/services/CanvasService.ts`. Local exploitation could allow unauthorized file system operations, and the project was notified early.
Azərbaycanca: Bu boşluq bazylhorsey obsidian-mcp-server 1.0.0 versiyasında `src/services/CanvasService.ts` faylındakı `readCanvas`/`writeCanvas` funksiyalarına təsir edən path traversal zəifliyidir. Lokal istismar nəticəsində fayl sistemi üzərində icazəsiz əməliyyatlar aparıla bilər, layihəyə erkən mərhələdə məlumat verilib.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which version of obsidian-mcp-server is affected by CVE-2026-19331?
CVE-2026-19331 affects version 1.0.0 of bazylhorsey obsidian-mcp-server.
Which functions are affected by the CVE-2026-19331 path traversal vulnerability?
This path traversal vulnerability affects the `readCanvas` and `writeCanvas` functions in the `src/services/CanvasService.ts` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.