Insecure URL Handling in Obsidian by Obsidian Systems
CVE-2021-38148
9.8CRITICAL
What is CVE-2021-38148?
The Obsidian application prior to version 0.12.12 lacks proper user confirmation for opening non-http/https URLs. This oversight may lead to users being misled into opening potentially harmful links without adequate warnings or permissions, increasing the risk of exposure to security threats.
