CVE-2026-104078 debrief based on the supplied source corpus. Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted href value with a TAB byte in the URL scheme. This vulnerability causes filterURL to produce an empty protocol that bypasses the configured safeProtocols restrict [truncated]
A remote code execution vulnerability exists in Obsidian Desktop before version 1.14.0. The vulnerability is due to insufficient sanitization of the data-background-iframe attribute in Markdown notes, which can be exploited by crafting malicious notes that bypass DOMPurify and are processed by the bundled Reveal.js 4.3.1 within the Slides core plugin. This allows a javascript: URL to execute in the result [truncated]