Obsidian

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 6
    Known Exploited: 0
    1
    Critical Level Threats
    4
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-2110

    Obsidian Local File Disclosure

    Last Modified: Nov 21, 2024
    Published: Aug 19, 2023

    CVE-2023-33244

    Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.

    Last Modified: Jan 31, 2025
    Published: May 20, 2023

    CVE-2023-27035

    An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

    Last Modified: Jan 30, 2025
    Published: May 01, 2023

    CVE-2022-36450

    Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.

    Last Modified: Nov 21, 2024
    Published: Jul 25, 2022

    CVE-2021-42057

    Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.

    Last Modified: Nov 21, 2024
    Published: Nov 04, 2021
    Items Per Page