---
id: CVE-2026-104078
title: >-
  Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the
  bundled MathJax 3.2.2 Safe component that allows attackers to execute
  arbitrary code by embedding a crafted \href value with a TAB byte in the URL
  scheme, causi…
summary: >-
  Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the
  bundled MathJax 3.2.2 Safe component that allows attackers to execute
  arbitrary code by embedding a crafted \href value with a TAB byte in the URL
  scheme, causi…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
  - CWE-1188
vendor: Obsidian
product: Obsidian Desktop
affected:
  - desktop < 1.14.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T18:17:13.277'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104078'
references:
  - url: 'https://obsidian.md/changelog/2026-10-05-desktop-v1.14.4/'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T17:58:08.570317Z'
ingestedAt: '2026-10-08T16:52:14.784Z'
---

## Overview

Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formula that renders as a javascript: URL anchor, which when clicked by the victim in Live Preview executes in the Node-integration-enabled vault renderer via require('child_process'), achieving arbitrary operating system command execution as the desktop user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
