Vulnerabilities > Obsidian

DATE CVE VULNERABILITY TITLE RISK
2023-08-19 CVE-2023-2110 Path Traversal vulnerability in Obsidian
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>".
local
low complexity
obsidian CWE-22
7.1
2023-05-20 CVE-2023-33244 Unspecified vulnerability in Obsidian
Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.
network
low complexity
obsidian
8.2
2023-05-01 CVE-2023-27035 Incorrect Default Permissions vulnerability in Obsidian 1.1.9
An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.
network
low complexity
obsidian CWE-276
7.5
2022-07-25 CVE-2022-36450 Improper Input Validation vulnerability in Obsidian
Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.
network
low complexity
obsidian CWE-20
critical
9.8
2021-11-04 CVE-2021-42057 Code Injection vulnerability in Obsidian Dataview
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection.
network
obsidian CWE-94
critical
9.3
2021-08-07 CVE-2021-38148 Unspecified vulnerability in Obsidian
Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.
network
low complexity
obsidian
7.5