CVE-2025-58401: Medium severity Obsidian GitHub Copilot Plugin vulnerability
Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58401?
CVE-2025-58401 is classified as a high severity vulnerability due to the potential for unauthorized access to user Github accounts.
How do I fix CVE-2025-58401?
To mitigate CVE-2025-58401, update the Obsidian GitHub Copilot Plugin to version 1.1.7 or later.
What specific vulnerability does CVE-2025-58401 address?
CVE-2025-58401 addresses the issue of storing Github API tokens in cleartext, which can be exploited by attackers.
Which versions of the Obsidian GitHub Copilot Plugin are affected by CVE-2025-58401?
CVE-2025-58401 affects all versions of the Obsidian GitHub Copilot Plugin prior to 1.1.7.
What are the potential impacts of CVE-2025-58401?
The potential impacts of CVE-2025-58401 include unauthorized operations on the linked Github account, leading to data exposure or manipulation.