{"id":"CVE-2021-42057","aliases":["GHSA-xfg5-vrmc-24wc"],"url":"https://o3.security/vulnerability/CVE-2021-42057","summary":"Obsidian Dataview vulnerable to code injection due to unsafe eval","details":"Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.","published":"2021-11-04T21:15:09.080Z","modified":"2026-07-09T06:35:32.691765Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"obsidian-dataview","fixedVersion":"0.4.13"}],"fix":null,"references":[{"type":"REPORT","url":"https://github.com/blacksmithgu/obsidian-dataview/issues/615"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T06:35:32.691765Z"}}