Obsidian Web MCP 是 Obsidian 知识库(vault)的一个安全远程 MCP 服务器。在 0.2.0 版本之前, 端点会在未执行登录、授权确认或会话检查的情况下直接签发授权码,而 端点又能将该授权码兑换为静态令牌 ,且在此过程中未对客户端进行身份认证。因此,任何能够访问目标隧道部署环境的未认证远程调用者均可调用 接口,并对整个知识库执行 (读取)、 (写入)、 (搜索)、 (列表)、 (移动)和 (删除)等操作。可选的 PKCE 机制无法阻止由攻击者发起的授权流程,而未认证的 端点还会通过返回
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jimprosser | obsidian-web-mcp | < 0.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jimprosser | obsidian-web-mcp | < 0.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet