Remote Code Execution Vulnerability in Obsidian Desktop by Obsidian
CVE-2026-104077

8.5HIGH

Key Information:

Vendor

Obsidian

Vendor
CVE Published:
8 October 2026

What is CVE-2026-104077?

Obsidian Desktop prior to version 1.14.0 has a vulnerability allowing attackers to remotely execute code by exploiting poor sanitization of the data-background-iframe attribute in Markdown notes. This flaw leverages a JavaScript URL that can be executed within a background iframe, facilitated by bundled Reveal.js 4.3.1. Given that Node integration is enabled and context isolation is disabled, malicious scripts can gain access to Node APIs, enabling attackers to run arbitrary operating system commands when the affected note is opened in presentation mode.

Affected Version(s)

Obsidian Desktop 0 < 1.14.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CodeAnt AI Security Research Team
.