Site icon API Security Blog

JVN#41633999: Obsidian GitHub Copilot Plugin stores sensitive information in cleartext

image
Obsidian GitHub Copilot Plugin provided by Pierre-Adrien Vasseur is vulnerable to the following vulnerability. Cleartext storage of sensitive information (CWE-312) CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:L Base Score 5.1 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L Base Score 6.8 CVE-2025-58401 ## Impact An attacker may obtain the GitHub API token used by the plugin and perform unauthorized operations on the linked GitHub account. ## Solution Update the Software Update the software to the latest version according to the information provided by the developer. ## Products Affected Obsidian GitHub Copilot Plugin versions prior to…Read More

Exit mobile version