VYPR

Obsidian Dataview

by Obsidian

CVEs (1)

  • CVE-2021-42057HigNov 4, 2021
    risk 0.51cvss 7.8epss 0.01

    Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.