IA Squad
SearchPT
js · @bitbonsai/mcpvaultHeads-up

@bitbonsai/mcpvault PathFilter now case-insensitive and canonicalizes per segment

PathFilter in @bitbonsai/mcpvault now uses case-insensitive matching and per-segment canonicalization before deny-list checks, fixing bypasses on case-insensiti

19 Jun 2026Read 1 minSeverity: schedule it

What changed

PathFilter in @bitbonsai/mcpvault now uses case-insensitive matching and per-segment canonicalization before deny-list checks, fixing bypasses on case-insensitive filesystems (macOS, Windows) and Windows trailing dots/spaces.

Who it affects

Users of @bitbonsai/mcpvault on macOS or Windows, or anyone relying on PathFilter's deny-list for .git, .obsidian, node_modules, etc.

What to do today

Update to version 0.11.4 or later to prevent bypasses of path restrictions.

The trail
Collected Audited Written Published