Critical severity9.8NVD Advisory· Published Aug 7, 2021· Updated Jun 17, 2026
CVE-2021-38148
CVE-2021-38148
Description
Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
obsidiannpm | < 0.12.12 | 0.12.12 |
Affected products
3- Obsidian/Obsidiandescription
Patches
Vulnerability mechanics
References
4- forum.obsidian.md/t/obsidian-release-v0-12-12/21564nvdRelease NotesVendor Advisory
- github.com/advisories/GHSA-45mx-g85m-wwm3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-38148ghsaADVISORY
- web.archive.org/web/20210807011714/https://forum.obsidian.md/t/obsidian-release-v0-12-12/21564ghsaWEB
News mentions
0No linked articles in our index yet.