Obsidian Desktop before 1.14.0 contains an arbitrary code execution vulnerability in the Slides core plugin that allows attackers to craft a malicious Markdown note containing a data-background-iframe attribute that survives DOMPurify sanitization. When the victim opens the note and starts it as a presentation, Reveal.js promotes the attacker-controlled value to an iframe src without URL-scheme restrictions, executing a javascript: payload that reaches Node.js APIs via parent.require in the Node-integrated, context-isolation-disabled renderer to achieve arbitrary command execution as the Obsidian user.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Obsidian Desktop before 1.14.0 contains an arbitrary code execution vulnerability in the Slides core plugin that allows attackers to craft a malicious Markdown note containing a data-background-iframe attribute that survives DOMPurify sanitization. When the victim opens the note and starts it as a presentation, Reveal.js promotes the attacker-controlled value to an iframe src without URL-scheme restrictions, executing a javascript: payload that reaches Node.js APIs via parent.require in the Node-integrated, context-isolation-disabled renderer to achieve arbitrary command execution as the Obsidian user.
Title Obsidian Desktop < 1.14.0 RCE via Slides Plugin Markdown
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T16:36:33.740Z

Reserved: 2026-10-01T18:02:50.083Z

Link: CVE-2026-104077

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses