VYPR

Obsidian Desktop

by Obsidian

CVEs (2)

  • CVE-2026-104078HigOct 8, 2026
    risk 0.51cvss 7.8epss —

    Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol…

  • CVE-2026-104077HigOct 8, 2026
    risk 0.51cvss 7.8epss —

    Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js…