Obsidian Desktop before 1.14.0 contains an arbitrary code execution vulnerability in the Slides core plugin that allows attackers to craft a malicious Markdown note containing a data-background-iframe attribute that survives DOMPurify sanitization. When the victim opens the note and starts it as a presentation, Reveal.js promotes the attacker-controlled value to an iframe src without URL-scheme restrictions, executing a javascript: payload that reaches Node.js APIs via parent.require in the Node-integrated, context-isolation-disabled renderer to achieve arbitrary command execution as the Obsidian user.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://obsidian.md/changelog/2026-10-05-desktop-v1.14.4/ |
|
History
Thu, 08 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Obsidian Desktop before 1.14.0 contains an arbitrary code execution vulnerability in the Slides core plugin that allows attackers to craft a malicious Markdown note containing a data-background-iframe attribute that survives DOMPurify sanitization. When the victim opens the note and starts it as a presentation, Reveal.js promotes the attacker-controlled value to an iframe src without URL-scheme restrictions, executing a javascript: payload that reaches Node.js APIs via parent.require in the Node-integrated, context-isolation-disabled renderer to achieve arbitrary command execution as the Obsidian user. | |
| Title | Obsidian Desktop < 1.14.0 RCE via Slides Plugin Markdown | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T16:36:33.740Z
Reserved: 2026-10-01T18:02:50.083Z
Link: CVE-2026-104077
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses