Security
- Fixed a critical authentication bypass in password-gated OAuth (GHSA-cc9w-6w4g-hqv7).
/oauth/tokenissued an access token for any authorization code that was in flight, without checking that the password step had completed. Because the code is created and shown on the authorize page before any password is entered, anyone who could reach a server started withMCP_AUTH_TOKENcould read the code and redeem it directly, gaining full vault access without the password. The code is now redeemable only after the password is accepted. If you run withMCP_AUTH_TOKENset, upgrade immediately and rotate the token. Reported by @sall.
Features
read_notedeclaresanthropic/maxResultSizeCharsso Claude Code returns a whole large note inline instead of a file pointer (#23). Contributed by @andreasd083.
Fixes
- Frontmatter keys and inline
#tagsnow accept Unicode letters, so non-ASCII tags (e.g.#lägen,#日本語) and keys are kept whole instead of being truncated or silently dropped (#22). Contributed by @andreasd083. - Inline tag parsing now follows Obsidian's own rules:
#tagsinside inline code spans and fenced code blocks are ignored, and all-numeric tags (e.g.#1984) are dropped (#24). Contributed by @andreasd083. delete_noteon a path that does not exist now returnsNote not foundinstead of falsely reportingDeleted(#26). Contributed by @andreasd083.npm audit fixto clear high-severity transitive advisories (axios, undici, brace-expansion); mcp-proxy stays pinned at 6.4.4.