Obsidian
Obsidian: vulnerabilidades y CVE
Obsidian tiene 7 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses2
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-57442 | Media (6.9) | 0.19% | — | 15 sept 2026 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian,… |
| CVE-2026-42889 | Crítica (9.1) | 0.53% | — | 12 may 2026 | Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured, WebSocket… |
| CVE-2023-2110 | Alta (7.1) | 0.36% | — | 19 ago 2023 | Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This… |
| CVE-2023-33244 | Alta (8.2) | 0.47% | — | 20 may 2023 | Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page. |
| CVE-2023-27035 | Alta (7.5) | 1.8% | — | 1 may 2023 | An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page. |
| CVE-2022-36450 | Crítica (9.8) | 20% | — | 25 jul 2022 | Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL. |
| CVE-2021-38148 | Crítica (9.8) | 1.2% | — | 7 ago 2021 | Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs. |