Obsidian
Products
4- 5 CVEs
- 5 CVEs
- 1 CVE
- 0 CVEs
Recent CVEs
7| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-38148 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2021 | Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs. | ||
| CVE-2022-36450 | Hig | 0.54 | 8.0 | 0.20 | Jul 25, 2022 | Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL. | ||
| CVE-2023-2110 | Hig | 0.53 | 8.2 | 0.00 | Aug 19, 2023 | Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/". This vulnerability can be exploited if a user opens a malicious… | ||
| CVE-2023-33244 | Hig | 0.53 | 8.2 | 0.00 | May 20, 2023 | Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page. | ||
| CVE-2021-42057 | Hig | 0.51 | 7.8 | 0.01 | Nov 4, 2021 | Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases. | ||
| CVE-2023-27035 | Med | 0.42 | 6.5 | 0.02 | May 1, 2023 | An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page. | ||
| CVE-2025-58401 | Med | 0.37 | 6.8 | 0.00 | Sep 5, 2025 | Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account. |
- risk 0.64cvss 9.8epss 0.01
Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.
- risk 0.54cvss 8.0epss 0.20
Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.
- risk 0.53cvss 8.2epss 0.00
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/". This vulnerability can be exploited if a user opens a malicious…
- risk 0.53cvss 8.2epss 0.00
Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.
- risk 0.51cvss 7.8epss 0.01
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.
- risk 0.42cvss 6.5epss 0.02
An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.
- risk 0.37cvss 6.8epss 0.00
Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.