MCPVault path filters bypassed: CVE-2026-57441 and CVE-2026-57442
Two advisories in MCPVault, which restricts which directories a language model can read, describe path-filter bypasses: CVE-2026-57441 (CVSS 8.4) and CVE-2026-57442 (CVSS 6.9). Both stem from comparing a path as a string instead of the filesystem-resolved path.
- CVE-2026-57441: on case-insensitive filesystems a case variant of .git or node_modules passes the string check
- CVE-2026-57442: the deny list is anchored at the root and misses nested .git and .obsidian directories
- Fix: resolve paths to canonical form and check at the point of use
- Operators should run the server as a user limited to required directories
Read next
Security