Back to database
Act now84High8.4VulnerabilityCVE-2026-104078No patch link observed

CVE-2026-104078 — Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute …

Published Oct 8, 2026, 05:17 PM UTCIngested 4h agoSource NVD(cve-db)CVE-2026-104078

Description

Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formula that renders as a javascript: URL anchor, which when clicked by the victim in Live Preview executes in the Node-integration-enabled vault renderer via require('child_process'), achieving arbitrary operating system command execution as the desktop user.

CVSS v4.0 base metrics

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
8.4

High severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Local

Attack Vector

AC

Low

Attack Complexity

AT

None

Attack Requirements

PR

None

Privileges Required

UI

Active

User Interaction

VC

High

Confidentiality (Vulnerable System)

VI

High

Integrity (Vulnerable System)

VA

High

Availability (Vulnerable System)

SC

None

Confidentiality (Subsequent System)

SI

None

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)