CVE-2026-54618

CVE-2026-54618 published: Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MCP_TOKEN without auth...

View full NVD advisory → ← Back to CVE watch