Obsidian 1.13.1

Obsidian 1.13.1

Obsidian  ❘ Freeware
Android iOS Windows Mac
Rank 6 among competitors
Latest Version
1.13.1
Virus checked

Here are recurring questions and related user issues:

Has Obsidian (the note‑taking app) had any known security vulnerabilities, and were they fixed?

Yes. Over the years several CVEs have been published and subsequently patched. Examples include CVE‑2023‑2110 (a local file disclosure via app://local/... fixed in 1.2.8), CVE‑2023‑33244 (embedded web pages could call unintended APIs like mic/camera; fixed in 1.2.2), CVE‑2023‑27035 (Canvas 1.1.9 allowed embedded sites to trigger notifications and record audio; addressed in later releases), CVE‑2022‑36450 (a custom‑scheme issue leading to possible RCE; fixed in 0.15.5), and CVE‑2021‑38148 (non‑HTTP(S) URL confirmation bypass; fixed in 0.12.12).

Are community plugins safe, and what real problems have users encountered?

Community plugins run JavaScript with access to your vault and can make network requests. Obsidian mitigates risk with "Restricted mode" (formerly "Safe mode"), an initial review before a plugin enters the official directory, and developer rules (for example, no client‑side telemetry). However, the team does not review every plugin update; users have previously flagged issues such as a plugin sending telemetry and being removed from the store.

Is Obsidian Sync truly end‑to‑end encrypted (E2EE), and can users verify it themselves?

Obsidian Sync uses end‑to‑end encryption so that only you hold the keys; even file names are encrypted. The team published a step‑by‑step guide showing how to independently verify E2EE in your own vault, and they periodically upgrade the encryption scheme.

Are my local Obsidian notes encrypted at rest by default?

No. By design, Obsidian stores your notes as plain‑text Markdown files in a local "vault" folder. Local‑at‑rest encryption is left to the user or the operating system (for example, FileVault, BitLocker, LUKS) or third‑party tools/containers; Obsidian's privacy posture emphasizes local‑first storage, with optional E2EE only when using Sync.

Can embedded web content or iframes inside notes access my camera/microphone or otherwise break out?

Historically there were vulnerabilities where embedded pages could invoke sensitive APIs. Notably, CVE‑2023‑33244 allowed calls to mic/camera/notifications from an embedded page (fixed in 1.2.2), and CVE‑2023‑27035 affected Canvas embeds (fixed in later 1.1.x builds). Keeping Obsidian current mitigates these; the issues were disclosed and patched.

Could a malicious link executed from Obsidian cause code execution or data exfiltration?

Earlier releases had scheme‑handling issues. CVE‑2022‑36450 (pre‑0.15.5) involved obsidian://hook-get-address leading to remote code execution, and CVE‑2023‑2110 (pre‑1.2.8) allowed local file disclosure via a crafted page. Both were fixed quickly; users should update promptly and be cautious with untrusted links or notes imported from unknown sources.

Have there been plugin‑specific security vulnerabilities?

Yes. A prominent example is the Dataview plugin vulnerability (CVE‑2021‑42057), which allowed "eval injection" that could execute attacker‑controlled code when opening a malicious Markdown file; mitigations landed in Dataview 0.4.13. See CVE‑2021‑42057 (NVD) and the plugin’s own issue thread documenting the flaw and fix.

What independent audits exist for Obsidian?

Obsidian commissions annual third‑party audits by Cure53 covering the desktop and mobile clients. The 2023 and 2024 assessments included penetration testing and source‑code review; Cure53 reported that all identified issues were addressed. You can read the summaries and the full reports from Obsidian’s Security page.

Does Obsidian collect telemetry or send my content to its servers?

The core app does not collect telemetry, and you can run it entirely offline. Obsidian connects to the internet only for features you opt into (for example, checking for updates, browsing the community directory, or using Sync/Publish), and community plugins listed in the official directory are prohibited from capturing client‑side telemetry.

What network calls does Obsidian make, and can enterprises restrict them?

The "Security considerations for teams" page enumerates the domains used for updates, account/license checks, Sync, and Publish; it also notes that these HTTPS connections can be blocked by domain firewalling or application lockdown if you require an offline deployment.

Are Obsidian Publish sites private or indexed by search engines, and can I password‑protect them?

Publish is public by default, but you can set a site‑wide password; note‑level passwords are not supported. There is also an option to disallow search engine indexing in site options.

Where are Obsidian Sync servers hosted, and can I pick a region?

Obsidian Sync runs on DigitalOcean infrastructure with geo‑regional hosting options that are selected when you first set up a remote vault. The Sync security page documents current locations and how region selection works.

Please note: These references and incidents are specific to Obsidian the note‑taking app (obsidian.md). They do not refer to similarly named products such as Plesk “Obsidian” or the cybersecurity vendor “Obsidian Security,” which have unrelated CVEs and policies.

Screenshots (Click to view larger)

Installations

283 users of UpdateStar had Obsidian installed last month.

Alternatives


Microsoft OneNote

Organize your notes effortlessly with Microsoft OneNote.

Documentos

Organize and collaborate seamlessly with Documentos by Google\Chrome.

Evernote

Organize your thoughts and ideas with Evernote.

AppWizard

Simplify Your App Development with AppWizard

IjroOffice

Boost Your Productivity with IjroOffice's Comprehensive Suite of Tools

Joplin

Joplin: Your Personal Note-Taking Companion

Related


AI Note Taker NoteGPT AI Agent

Knotes is a professional-grade AI note-taking and task management tool, developed using GPT-4o and Gemini. Designed to enhance productivity and streamline information management, it offers a range of features aimed at …

AI Notes Voice to Text AI Chat

Caution Advised for AI Notes Voice to Text App Due to User Complaints

AI Notes, Ask AI Chat to Write

Revolutionize Note-Taking with AI Notes by ChatGenies

AI Voice to Text AI Note Taker

As a reviewer, I find Knotes to be a comprehensive AI note-taking application that leverages advanced language models such as GPT-5 and Gemini to enhance productivity and organization.

Crowdsource

Unlock Collective Intelligence with Crowdsource by Google

Google Analytics

Unlock the Power of Data with Google Analytics
Secure and free downloads checked by UpdateStar

Stay up-to-date
with UpdateStar freeware.

Latest Reviews

Everything Search Engine Everything Search Engine
Effortlessly find any file on your computer with Everything Search Engine.
Đấu Trường Chân Lý Đấu Trường Chân Lý
Đấu Trường Chân Lý — Giao tranh chiến lược hấp dẫn với vài trục trặc trên mobile
Thunderbolt™ Software Thunderbolt™ Software
Enhance Your Thunderbolt™ Experience with Intel's Software
WeChat WeChat
Connect with friends and family with WeChat by 腾讯科技(深圳)有限公司
Kalorické Tabulky Kalorické Tabulky
Effortlessly Track Your Nutrition with Kalorické Tabulky
FiveM FiveM
Enhance Your GTA V Gameplay with FiveM
UpdateStar Premium Edition UpdateStar Premium Edition
Keeping Your Software Updated Has Never Been Easier with UpdateStar Premium Edition!
Google Chrome Google Chrome
Fast and Versatile Web Browser
Microsoft Edge Microsoft Edge
A New Standard in Web Browsing
Microsoft Visual C++ 2015 Redistributable Package Microsoft Visual C++ 2015 Redistributable Package
Boost your system performance with Microsoft Visual C++ 2015 Redistributable Package!
Microsoft OneDrive Microsoft OneDrive
Streamline Your File Management with Microsoft OneDrive
Microsoft Visual C++ 2010 Redistributable Microsoft Visual C++ 2010 Redistributable
Essential Component for Running Visual C++ Applications

Latest Updates


Chub AI 0.3.7

Chub AI: The Smart Assistant Redefining Efficiency

Porter Driver Partner App 5.132.1

Efficient Fleet Management with Porter Driver Partner App

Findlyy – Spot the Differences 3.0.2.50

Discover the challenge of finding differences with Spot the Difference – Hidden Object Game, a thoughtfully designed puzzle experience that tests keen observation and quick decision-making skills.

국민신문고 3.3.9

The Citizen Complaint Center is an online communication platform where citizens can submit all their complaints, citizen suggestions, and policy discussions to the government.

تأميني | Tameeni 5.23.10

Discover and compare car insurance offers and prices from over 20 approved insurance companies in the Kingdom in just minutes. With Tameeni, the insurance experience is made easier and more convenient.

Hofmann - Álbumes de fotos 251

Celebrating Black Friday by creating lasting memories offers an excellent opportunity to transform personal moments into tangible keepsakes.