A self-hosted MCP server with a management UI for reading, searching, editing, and organizing notes in an Obsidian vault, with OAuth and token authentication, git snapshots, and optional Obsidian Sync.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Hono vulnerable to arbitrary file access via serveStatic vulnerability
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo
Hono: Path traversal in toSSG() allows writing files outside the output directory
Hono missing validation of cookie name on write path in setCookie()
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
process.env. You'll be asked to provide them before it can run.CLOUDFLARED_BINCLOUDFLARED_TUNNEL_TOKENDATA_DIR— /data Root for all persistent stateGATECRASH_BINGATECRASH_HOST_KEYGATECRASH_SERVERGATECRASH_TARGETGATECRASH_TOKENLOG_LEVEL— info debug / info / warn / errorOB_BINPORT— 3000 Listen portPUBLIC_URL[](https://m8ven.ai/mcp/jclement-obsidian-mcp-26bj31)