在 Obsidian Desktop 1.14.0 之前的版本中,Slides 核心插件存在一个任意代码执行漏洞。攻击者可以构造一个恶意的 Markdown 笔记,其中包含一个能够绕过 DOMPurify 清理过滤的 属性。当受害者打开该笔记并将其作为演示文稿启动时,Reveal.js 会将攻击者控制的值提升为 iframe 的 属性,且未对 URL 协议进行限制,从而执行 协议的有效负载。由于该渲染器启用了 Node.js 集成且禁用了上下文隔离,该有效负载可通过 访问 Node.js API,最终实现以当前 O
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Obsidian | Obsidian Desktop | < 1.14.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Obsidian | Obsidian Desktop | 0 ~ 1.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet