Vulnerabilities
Vulnerable Software
Obsidian:  >> Obsidian  >> 1.1.9  Security Vulnerabilities
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.
CVSS Score
8.2
EPSS Score
0.001
Published
2023-08-19
Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.
CVSS Score
8.2
EPSS Score
0.001
Published
2023-05-20
An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.
CVSS Score
6.5
EPSS Score
0.231
Published
2023-05-01


Contact Us

Shodan ® - All rights reserved