Описание
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.
Ссылки
- Release Notes
- ExploitMitigationThird Party Advisory
- Release Notes
- ExploitMitigationThird Party Advisory
Уязвимые конфигурации
Одновременно
Одно из
EPSS
8.2 High
CVSS3
7.1 High
CVSS3
Дефекты
Связанные уязвимости
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.
EPSS
8.2 High
CVSS3
7.1 High
CVSS3