← Back

Obsidian Dataview

obsidian_dataview

Vendor: Obsidian • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Obsidian
1Obsidian Dataview
Nov 21, 2024
Nov 4, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened....Show more
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.Show less