MCP server for Obsidian that exposes tools for reading/writing notes, managing frontmatter and tags, querying Tasks, semantic search, and interacting with Obsidian Bases, with shared local caching and support for various runtime modes.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
Hono: JWT middleware accepts any Authorization scheme, not only Bearer
Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
js-yaml has prototype pollution in merge (<<)
process.env. You'll be asked to provide them before it can run.HEADLESS_LONG_RUN_INTERVAL_SECONDSHEADLESS_LONG_RUN_MINUTESHEADLESS_LONG_RUN_OUTPUT_DIRHEADLESS_SERVER_CACHE_DIRHEADLESS_SERVER_VAULTHEADLESS_SNAPSHOT_DIRMCP_HTTP_HOST— "127.0.0.1"MCP_HTTP_PORTMCP_LOG_LEVELMCP_PROXY_START_TIMEOUT_MSMCP_SMOKE_HEALTH_URLMCP_SMOKE_HTTP_URLMCP_SMOKE_MIN_TOOLSMCP_SMOKE_STDIO_PROXYMCP_SMOKE_TIMEOUT_MSOBSIDIAN_SHARED_CACHE_DB_PATH— to move the shared SQLite fileOBSIDIAN_VAULT— If is not set, the server falls back to the parent vault inferred from SMART_ENV_DIR, then to the project root.OBSIDIAN_VAULT_EXCLUDE_PATTERNS— to add comma- or newline-separated gitignore-style exclusions on top of the built-in vault safety policy[](https://m8ven.ai/mcp/optimikelabs-optimike-obsidian-mcp-gp02fy)