Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-48753 | In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock. In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-2110 | Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/ ". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian. NVD description · AI analysis pending | 7.1 | <1% | PoC |
| — | |
| CVE-2023-33244 | Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page. Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page. NVD description · AI analysis pending | 8.2 | <1% |
| — | ||
| CVE-2023-27035 | An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page. NVD description · AI analysis pending | 7.5 | 2% | PoC ×2 |
| — | |
| CVE-2022-36450 | Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL. Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL. NVD description · AI analysis pending | 9.8 | 20% | PoC |
| — | |
| CVE-2021-42057 | Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases. NVD description · AI analysis pending | 7.8 | 1% | PoC |
| — | |
| CVE-2021-38148 | Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs. Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs. NVD description · AI analysis pending | 9.8 | 1% |
| — |