Code Execution Vulnerability in Obsidian Desktop by Obsidian
CVE-2026-104078
8.4HIGH
What is CVE-2026-104078?
Obsidian Desktop is affected by a filter bypass vulnerability in the bundled MathJax component that allows attackers to execute arbitrary code. Malicious users can craft a note with a specially formatted MathJax formula containing a TAB byte in the URL scheme. When a victim interacts with this note in Live Preview, it triggers the execution of an arbitrary process on the desktop system through Node integration, exploiting the vulnerability in the filtering process. Users are advised to update to the latest version to mitigate this risk.
Affected Version(s)
Obsidian Desktop 0 < 1.14.0
