Vulnerability Description
Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Pierrad/obsidian-github-copilot/releases/tag/1.1.7
- https://jvn.jp/en/jp/JVN41633999/
FAQ
What is CVE-2025-58401?
CVE-2025-58401 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.
How severe is CVE-2025-58401?
CVE-2025-58401 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-58401?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.