Unrated severityNVD Advisory· Published Jul 25, 2022· Updated Aug 3, 2024
CVE-2022-36450
CVE-2022-36450
Description
Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Obsidian/Obsidiandescription
- Range: >=0.14.0,<0.15.5
Patches
Vulnerability mechanics
References
2- forum.obsidian.md/t/possible-remote-code-execution-through-obsidian-uri-scheme/39743mitrex_refsource_MISC
- www.chtsecurity.com/news/f2a1ad21-3442-495f-8b6e-f0fe433d6caamitrex_refsource_MISC
News mentions
0No linked articles in our index yet.