CVE-2023-27035
NixOS vulnerability analysis and mitigation

Overview

An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page. The vulnerability was discovered in February 2023 and affects Obsidian versions prior to 1.1.14 (Obsidian Forum, CVE Details).

Technical details

The vulnerability stems from the absence of a Session Permission Request handler in the Obsidian application. This allows malicious embedded websites to access sensitive Web APIs without requiring user permission or knowledge. The vulnerability has a CVSS v3.1 Base Score of 7.5 HIGH with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (CVE Details).

Impact

The vulnerability enables attackers to silently record the user's microphone, access the clipboard, and send desktop notifications without the user's knowledge or explicit permission grant. Unlike regular browsers that display permission request pop-ups, embedded websites in Obsidian Canvas can access these sensitive APIs without any notification to the user (GitHub POC).

Mitigation and workarounds

The vulnerability was fixed in Obsidian version 1.1.14 by implementing an Electron Session Permission Request handler to manage permission requests from embedded pages. Users should upgrade to version 1.1.14 or later. The fix ensures that access to Web APIs must be explicitly granted by the user or denied by default (Obsidian Forum).

Community reactions

The Obsidian development team responded quickly to the vulnerability report, implementing the suggested mitigation in code and releasing a fix in version 1.1.14. The team acknowledged the quality of the vulnerability report but noted they weren't yet participating in the CVE program due to being a small team (Obsidian Forum).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • firefox-x11
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox-x11
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management