PT-2021-23494 · Unknown · Obsidian Dataview

Tivey-Scwx

·

Published

2021-11-04

·

Updated

2022-05-24

·

CVE-2021-42057

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Obsidian Dataview versions 0.4.12-hotfix1 and earlier
Description The issue allows for eval injection due to the evalInContext function executing user input. This enables an attacker to craft malicious Markdown files that will execute arbitrary code once opened.
Recommendations For versions 0.4.12-hotfix1 and earlier, update to version 0.4.13 or later to mitigate the issue for some use cases. As a temporary workaround, consider restricting the use of the evalInContext function until a more comprehensive patch is available.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42057
GHSA-XFG5-VRMC-24WC

Affected Products

Obsidian Dataview