CVE-2023-27035

Source
https://cve.org/CVERecord?id=CVE-2023-27035
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-27035.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-27035
Published
2023-05-01T00:00:00Z
Modified
2026-08-12T03:51:29.353725309Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:U/UI:R CVSS Calculator
Summary
[none]
Details

An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/27xxx/CVE-2023-27035.json"
}
References

Affected packages

Git / github.com/obsidianmd/obsidian-releases

Affected ranges

Type
GIT
Repo
https://github.com/obsidianmd/obsidian-releases
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:obsidian:obsidian:1.1.9:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "1.1.9"
        },
        {
            "last_affected": "1.1.9"
        }
    ]
}

Affected versions

1.*
1.1.9
v1.*
v1.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-27035.json"