VYPR

Obsidian Canvas

by Obsidian

CVEs (5)

  • CVE-2022-36450HigJul 25, 2022
    risk 0.54cvss 8.0epss 0.20

    Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.

  • CVE-2023-2110HigAug 19, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/". This vulnerability can be exploited if a user opens a malicious…

  • CVE-2023-33244HigMay 20, 2023
    risk 0.53cvss 8.2epss 0.00

    Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.

  • CVE-2023-27035MedMay 1, 2023
    risk 0.42cvss 6.5epss 0.02

    An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

  • CVE-2025-58401MedSep 5, 2025
    risk 0.37cvss 6.8epss 0.00

    Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.