CVE-2021-42057: Code Injection
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.
Other sources
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Obsidian Dataview?
The vulnerability ID for Obsidian Dataview is CVE-2021-42057.
What is the severity of CVE-2021-42057?
The severity of CVE-2021-42057 is critical.
What is the affected software for CVE-2021-42057?
The affected software for CVE-2021-42057 is Obsidian Dataview through 0.4.12-hotfix1.
How does CVE-2021-42057 allow eval injection?
CVE-2021-42057 allows eval injection through the `evalInContext` function in Obsidian Dataview.
Is there a mitigation for CVE-2021-42057?
Yes, 0.4.13 provides a mitigation for some use cases of CVE-2021-42057.