📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

Obsidian Obsidian

Obsidian 1.13.6

Latest tracked version 1.13.6. Release status, tracked CVEs, and automated cross-platform patching for Obsidian.

Category: Productivity

PlatformLatest versionCVEs trackedLast checked
Windows1.13.652026-08-10

Known vulnerabilities (CVEs) in Obsidian

Lavawall tracks 5 published CVEs affecting Obsidian, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2023-332442023-05-20 19:15:09HIGH (8)Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.NETWORK
CVE-2023-270352023-05-01 22:15:10MEDIUM (8)An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.NETWORK
CVE-2023-21102023-08-19 06:15:46HIGH (8)Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.LOCAL
CVE-2022-364502022-07-25 07:15:08HIGH (10)Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.NETWORK
CVE-2021-381482021-08-07 03:15:07CRITICAL (10)Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.NETWORK

Why keeping Obsidian patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Obsidian release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches Obsidian

Lavawall® watches Obsidian releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Obsidian, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of Obsidian?
Lavawall tracks Obsidian at version 1.13.6 (last checked 2026-08-10). New releases are monitored continuously and can be deployed automatically across your fleet.
Does Obsidian have known security vulnerabilities (CVEs)?
Lavawall tracks 5 CVEs for Obsidian and remediates them automatically as part of patching.
How do I patch Obsidian automatically?
Deploy the Lavawall® agent and Obsidian updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for Obsidian through public information and proprietary statistical analysis, and can patch it automatically across your fleet.