Known Vulnerabilities for products from Obsidian
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Obsidian".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42889 json | Not Provided | 2026-05-12 | 2026-05-13 | |
| CVE-2025-65518 json | Not Provided | 2026-01-08 | 2026-07-15 | |
| CVE-2023-33244 json | Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an... | 8.2 - HIGH | 2023-05-20 | 2023-05-26 |
| CVE-2023-27035 json | An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and oth... | 7.5 - HIGH | 2023-05-01 | 2023-05-06 |
| CVE-2023-2110 json | Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local ... | 7.1 - HIGH | 2023-08-19 | 2023-08-24 |
| CVE-2022-36450 json | Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used... | 9.8 - CRITICAL | 2022-07-25 | 2022-10-26 |
| CVE-2021-42057 json | Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allo... | 7.8 - HIGH | 2021-11-04 | 2021-11-08 |
| CVE-2021-38148 json | Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs. | 9.8 - CRITICAL | 2021-08-07 | 2022-02-10 |