ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48753
In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.

In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.

NVD description · AI analysis pending
9.8<1% PoC
  • obsidiandynamics anode
CVE-2023-2110
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote

Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/ ". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.

NVD description · AI analysis pending
7.1<1% PoC
  • obsidian obsidian
CVE-2023-33244
Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.

Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.

NVD description · AI analysis pending
8.2<1%
  • obsidian obsidian
CVE-2023-27035
An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded

An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

NVD description · AI analysis pending
7.52% PoC ×2
  • obsidian obsidian
CVE-2022-36450
Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.

Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.

NVD description · AI analysis pending
9.820% PoC
  • obsidian obsidian
CVE-2021-42057
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection.

Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.

NVD description · AI analysis pending
7.81% PoC
  • obsidian obsidian dataview
CVE-2021-38148
Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.

Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.

NVD description · AI analysis pending
9.81%
  • obsidian obsidian