Impact
The vulnerability in Obsidian Desktop prior to version 1.14.0 exploits a bypass of the MathJax safe filter. By embedding a crafted \href value containing a TAB byte, the filterUrl function produces an empty protocol, allowing a javascript: URL anchor to be rendered. When a user clicks this anchor in Live Preview, the desktop’s Node‑integration‑enabled vault renderer invokes require('child_process'), enabling arbitrary operating system command execution as the desktop user. This code injection flaw aligns with CWE‑1188 and is also a form of reflected cross‑site scripting per CWE‑79.
Affected Systems
All installations of Obsidian Desktop with a version earlier than 1.14.0 are impacted. The affected product is Obsidian Desktop provided by Obsidian. Users of any older releases should consider upgrading to mitigate the risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4, indicating high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires the victim to open a note containing the crafted MathJax formula and click the resulting javascript: link, meaning the attack vector is user‑initiated within the local desktop environment. Given the high severity and the ability to execute arbitrary commands, the risk to affected users is significant.
OpenCVE Enrichment