CVE-2026-104077
Received Received - Intake

Remote Code Execution in Obsidian Desktop via Slides Plugin

Vulnerability report for CVE-2026-104077, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because Node integration is enabled and context isolation is disabled in Obsidian's vault renderer, the injected script can call parent.require() to access Node APIs such as fs and child_process, enabling arbitrary operating system command execution when the victim opens the note and manually starts the presentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Obsidian Obsidian Desktop 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1188 The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Obsidian Desktop before 1.14.0 has a remote code execution vulnerability due to insufficient sanitization of the data-background-iframe attribute in Markdown notes. Attackers can craft malicious notes that bypass DOMPurify and exploit the bundled Reveal.js 4.3.1 in the Slides core plugin to inject a javascript: URL into a background iframe. With Node integration enabled and context isolation disabled, the injected script can call parent.require() to access Node APIs like fs and child_process, enabling arbitrary OS command execution when the victim opens the note and starts the presentation.

Detection Guidance

This vulnerability can be detected by checking the Obsidian Desktop version installed on your system. If you are running a version prior to 1.14.0, your system may be vulnerable. Update to version 1.14.0 or later to mitigate the risk.

Impact Analysis

If exploited, this vulnerability allows attackers to execute arbitrary code on your system. This could lead to unauthorized access to files, installation of malware, data theft, or system compromise. The attack requires the victim to open a malicious note and manually start the presentation, making it dependent on user interaction.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information. The arbitrary code execution could allow attackers to exfiltrate, modify, or delete regulated data, resulting in non-compliance with these standards.

Mitigation Strategies

Update Obsidian Desktop to version 1.14.0 or later to address the iframe injection vulnerability in the Slides plugin.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104077. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart