O
Obsidian
Security Risk Profile
71
/100
highSecurity Risk Score
Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 7, 2021 to present
12
Total CVEs
10
Critical+High
0
Exploited
8
Unpatched
Threat Assessment
Avg CVSS
8.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
71/100
high
🆕 2Fresh (<7d)📈 2 in Last 30 Days
Severity Distribution
Critical
4High
6Medium
2Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
XSS
3
2
Path Traversal
1
3
Input Validation
1
4
Code Injection
1
Most Affected Products
1. Obsidian Obsidian5
2. Obsidian Obsidian Dataview3
3. Obsidian Obsidian Desktop2
4. Obsidian Relay Server1
5. Obsidian Scheduler1
Recent Vulnerabilities
See more →CVE-2026-104078
CVSS 8.4high
Obsidian Desktop < 1.14.0 RCE via MathJax Safe Filter Bypass
Oct 8, 2026🔧 No Patch
CVE-2026-104077
CVSS 8.5high
Obsidian Desktop < 1.14.0 RCE via Slides Plugin Markdown
Oct 8, 2026🔧 No Patch
CVE-2026-42889
CVSS 9.1critical
Relay Server WebSocket authentication bypass when token is omitted
May 12, 2026🔧 No Patch
CVE-2025-56449
CVSS 8.2high
Sep 29, 2025🔧 No Patch
CVE-2025-58401
CVSS 6.8medium
Sep 5, 2025🔧 No Patch
CVE-2022-36677
CVSS 6.1medium
Jan 5, 2024🔧 No Patch
CVE-2023-2110
CVSS 8.2high
Obsidian Local File Disclosure
Aug 19, 2023🔧 No Patch
CVE-2023-33244
CVSS 8.2high
May 20, 2023🔧 No Patch
CVE-2023-27035
CVSS 7.5high
May 1, 2023🔧 No Patch
CVE-2022-36450
CVSS 9.8critical
Jul 25, 2022🔧 No Patch
Monitor Obsidian in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.