Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability has been identified in Obsidian Web MCP, a secure remote server for Obsidian vaults. This issue allows unauthenticated remote attackers to access and manipulate vault data, potentially leading to unauthorized data access or modification. The primary concern is confirming the relevance and exposure of this technology within our environment.
- Unauthenticated remote vault data access.
- Critical if Obsidian Web MCP is in use.
- Assess relevance and exposure; take action.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can gain full access to an Obsidian vault by sending specially crafted requests to the /oauth/authorize and /oauth/token endpoints. These endpoints incorrectly issue authorization codes and exchange them for a static token, bypassing necessary checks. If successful, an attacker could read, write, search, list, move, or delete vault data.
- No authentication needed for access.
- Bypasses login and consent checks.
- Full vault data compromise.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated remote caller could gain unauthorized access to an Obsidian vault's data and perform actions such as reading, writing, searching, listing, moving, and deleting files. This could occur when the system's /oauth/authorize and /oauth/token endpoints are improperly handled, allowing the static VAULT_MCP_TOKEN to be exchanged without proper authentication or consent. The optional PKCE mechanism does not prevent this flow, and an unauthenticated /oauth/register endpoint may also expose client credentials.
- Vault data integrity and confidentiality.
- Unauthenticated remote access to sensitive operations.
- Complete vault data compromise or modification.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Obsidian Web MCP product, used for secure remote access to Obsidian vaults, is likely managed by application owners or platform teams responsible for deployed services. The initial step is to locate all instances of this technology, verify their network reachability and business criticality, identify the accountable owner, and then prioritize remediation based on the assessed risk.
- Application owners should address this.
- Verify public exposure and asset criticality.
- Plan remediation based on risk assessment.