Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://obsidian.md/changelog/2026-10-05-desktop-v1.14.4/ |
|
Thu, 08 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formula that renders as a javascript: URL anchor, which when clicked by the victim in Live Preview executes in the Node-integration-enabled vault renderer via require('child_process'), achieving arbitrary operating system command execution as the desktop user. | |
| Title | Obsidian Desktop < 1.14.0 RCE via MathJax Safe Filter Bypass | |
| Weaknesses | CWE-1188 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T16:38:20.154Z
Reserved: 2026-10-01T18:02:50.083Z
Link: CVE-2026-104078
No data.
Status : Received
Published: 2026-10-08T17:17:11.753
Modified: 2026-10-08T17:17:11.753
Link: CVE-2026-104078
No data.
OpenCVE Enrichment
No data.