{"id":"GHSA-xfg5-vrmc-24wc","summary":"Obsidian Dataview vulnerable to code injection due to unsafe eval","details":"Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The `evalInContext` function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.","aliases":["CVE-2021-42057"],"modified":"2023-11-08T04:07:04.853275Z","published":"2022-05-24T19:19:42Z","database_specific":{"github_reviewed_at":"2023-10-19T18:29:49Z","nvd_published_at":"2021-11-04T21:15:00Z","cwe_ids":["CWE-94"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42057"},{"type":"WEB","url":"https://github.com/blacksmithgu/obsidian-dataview/issues/615"},{"type":"PACKAGE","url":"https://github.com/blacksmithgu/obsidian-dataview"}],"affected":[{"package":{"name":"obsidian-dataview","ecosystem":"npm","purl":"pkg:npm/obsidian-dataview"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.13"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.4.12-hotfix1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xfg5-vrmc-24wc/GHSA-xfg5-vrmc-24wc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}