{"id":"CVE-2026-104078","title":"Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \\href value with a TAB byte in the URL scheme, causi…","summary":"Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \\href value with a TAB byte in the URL scheme, causi…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-79","CWE-1188"],"vendor":"Obsidian","product":"Obsidian Desktop","affected":["desktop < 1.14.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T18:17:13.277","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104078","references":[{"url":"https://obsidian.md/changelog/2026-10-05-desktop-v1.14.4/","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-08T17:58:08.570317Z"},"ingestedAt":"2026-10-08T16:52:14.784Z","slug":"CVE-2026-104078","body":"## Overview\n\nObsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \\href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formula that renders as a javascript: URL anchor, which when clicked by the victim in Live Preview executes in the Node-integration-enabled vault renderer via require('child_process'), achieving arbitrary operating system command execution as the desktop user.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}