Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104078— Obsidian Desktop < 1.14.0 RCE via MathJax Safe Filter Bypass

Quick assessment

Affected
Obsidian Obsidian Desktop
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Obsidian Desktop 在 1.14.0 版本之前存在一个过滤绕过漏洞,该漏洞存在于捆绑的 MathJax 3.2.2 Safe 组件中。攻击者可以通过在 URL 方案中嵌入包含 TAB 字节的精心构造的 \href 值,导致 filterURL 函数生成一个空协议,从而绕过配置的 safeProtocols 限制,最终实现任意代码执行。攻击者可以构造一个包含恶意 MathJax 公式的笔记,该公式在渲染后会显示为一个 javascript: URL 锚点。当用户在 Live Preview(实时预览)模

CVSS 7.8 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
Obsidian Obsidian Desktop < 1.14.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104078

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Obsidian Desktop < 1.14.0 RCE via MathJax Safe Filter Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formula that renders as a javascript: URL anchor, which when clicked by the victim in Live Preview executes in the Node-integration-enabled vault renderer via require('child_process'), achieving arbitrary operating system command execution as the desktop user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Obsidian Obsidian Desktop 0 ~ 1.14.0 -

II. Public POCs for CVE-2026-104078

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104078

请登录查看更多情报信息。

Other References for CVE-2026-104078 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104078

No comments yet


Leave a comment