CVE-2023-2110: Obsidian Local File Disclosure
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2110?
CVE-2023-2110 is a vulnerability in Obsidian desktop before version 1.2.8 that allows a crafted webpage to access local files and exfiltrate them to remote web servers.
How does CVE-2023-2110 affect Obsidian?
CVE-2023-2110 affects Obsidian desktop versions before 1.2.8 on Windows, Linux, and macOS.
What is the severity of CVE-2023-2110?
The severity of CVE-2023-2110 is high with a CVSS score of 7.1.
How can CVE-2023-2110 be exploited?
CVE-2023-2110 can be exploited if a user opens a malicious markdown file in Obsidian.
How can CVE-2023-2110 be fixed?
CVE-2023-2110 can be fixed by updating Obsidian desktop to version 1.2.8 or later.