Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/
- https://starlabs.sg/advisories/23/23-2110/
No PoCs found on GitHub currently.