Remote Code Execution Vulnerability in Obsidian Desktop by Obsidian
CVE-2026-104077
8.5HIGH
What is CVE-2026-104077?
Obsidian Desktop prior to version 1.14.0 has a vulnerability allowing attackers to remotely execute code by exploiting poor sanitization of the data-background-iframe attribute in Markdown notes. This flaw leverages a JavaScript URL that can be executed within a background iframe, facilitated by bundled Reveal.js 4.3.1. Given that Node integration is enabled and context isolation is disabled, malicious scripts can gain access to Node APIs, enabling attackers to run arbitrary operating system commands when the affected note is opened in presentation mode.
Affected Version(s)
Obsidian Desktop 0 < 1.14.0
