← Back

Obsidian

obsidian

6 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Obsidian
obsidian

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Obsidian
1Obsidian
Nov 21, 2024
Aug 19, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnera...Show more
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.Show less
1Obsidian
1Obsidian
Jan 31, 2025
May 20, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.
1Obsidian
1Obsidian
Jan 30, 2025
May 1, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.
1Obsidian
1Obsidian
Nov 21, 2024
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.
1Obsidian
1Obsidian Dataview
Nov 21, 2024
Nov 4, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened....Show more
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.Show less
1Obsidian
1Obsidian
Nov 21, 2024
Aug 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.