Impact
Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because Node integration is enabled and context isolation is disabled in Obsidian's vault renderer, the injected script can call parent.require() to access Node APIs such as fs and child_process, enabling arbitrary operating system command execution when the victim opens the note and manually starts the presentation.
Affected Systems
Users of Obsidian Desktop versions prior to 1.14.0 that have the Slides plugin installed. The issue is limited to the desktop application and requires the user to open a malicious note and start a presentation.
Risk and Exploitability
The CVSS score is 8.5 and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is unavailable. Exploitation requires social engineering to deliver a note, but once opened the attacker can run commands with the desktop user’s privileges, indicating a high risk of remote code execution.
OpenCVE Enrichment