Security: coddingtonbear/obsidian-local-rest-api
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/deleteGHSA-62gx-5q78-wrvx published
Jun 4, 2026 by coddingtonbearHigh
Learn more about advisories related to coddingtonbear/obsidian-local-rest-api in the GitHub Advisory Database