Code Execution Vulnerability in Obsidian Desktop by Obsidian
CVE-2026-104078

8.4HIGH

Key Information:

Vendor

Obsidian

Vendor
CVE Published:
8 October 2026

What is CVE-2026-104078?

Obsidian Desktop is affected by a filter bypass vulnerability in the bundled MathJax component that allows attackers to execute arbitrary code. Malicious users can craft a note with a specially formatted MathJax formula containing a TAB byte in the URL scheme. When a victim interacts with this note in Live Preview, it triggers the execution of an arbitrary process on the desktop system through Node integration, exploiting the vulnerability in the filtering process. Users are advised to update to the latest version to mitigate this risk.

Affected Version(s)

Obsidian Desktop 0 < 1.14.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CodeAnt AI Security Research Team
.