Description
Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because Node integration is enabled and context isolation is disabled in Obsidian's vault renderer, the injected script can call parent.require() to access Node APIs such as fs and child_process, enabling arbitrary operating system command execution when the victim opens the note and manually starts the presentation.
Published: 2026-10-08
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Obsidian Desktop before 1.14.0 contains an arbitrary code execution vulnerability in the Slides core plugin that allows attackers to craft a malicious Markdown note containing a data-background-iframe attribute that survives DOMPurify sanitization. When the victim opens the note and starts it as a presentation, Reveal.js promotes the attacker-controlled value to an iframe src without URL-scheme restrictions, executing a javascript: payload that reaches Node.js APIs via parent.require in the Node-integrated, context-isolation-disabled renderer to achieve arbitrary command execution as the Obsidian user. Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because Node integration is enabled and context isolation is disabled in Obsidian's vault renderer, the injected script can call parent.require() to access Node APIs such as fs and child_process, enabling arbitrary operating system command execution when the victim opens the note and manually starts the presentation.
Weaknesses CWE-1188
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Thu, 08 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Obsidian Desktop before 1.14.0 contains an arbitrary code execution vulnerability in the Slides core plugin that allows attackers to craft a malicious Markdown note containing a data-background-iframe attribute that survives DOMPurify sanitization. When the victim opens the note and starts it as a presentation, Reveal.js promotes the attacker-controlled value to an iframe src without URL-scheme restrictions, executing a javascript: payload that reaches Node.js APIs via parent.require in the Node-integrated, context-isolation-disabled renderer to achieve arbitrary command execution as the Obsidian user.
Title Obsidian Desktop < 1.14.0 RCE via Slides Plugin Markdown
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T17:14:40.634Z

Reserved: 2026-10-01T18:02:50.083Z

Link: CVE-2026-104077

cve-icon Vulnrichment

Updated: 2026-10-08T17:14:36.478Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T17:17:11.603

Modified: 2026-10-08T21:33:42.423

Link: CVE-2026-104077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:00:07Z

Weaknesses