Vulnerability Description
Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Obsidian | Obsidian | >= 0.14.0, < 0.15.5 |
Related Weaknesses (CWE)
References
- https://forum.obsidian.md/t/possible-remote-code-execution-through-obsidian-uri-ExploitVendor Advisory
- https://www.chtsecurity.com/news/f2a1ad21-3442-495f-8b6e-f0fe433d6caaThird Party Advisory
- https://forum.obsidian.md/t/possible-remote-code-execution-through-obsidian-uri-ExploitVendor Advisory
- https://www.chtsecurity.com/news/f2a1ad21-3442-495f-8b6e-f0fe433d6caaThird Party Advisory
FAQ
What is CVE-2022-36450?
CVE-2022-36450 is a vulnerability with a CVSS score of 8.0 (HIGH). Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.
How severe is CVE-2022-36450?
CVE-2022-36450 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36450?
Check the references section above for vendor advisories and patch information. Affected products include: Obsidian Obsidian.