Audit Open Original ↗
Obsidian Sync
Type
Security review
Client
Obsidian
Date
2025-12
Domain
Crypto
Effort
2 wks
Section
Cryptography Reviews
Trail of Bits's security review of Obsidian (Dec 2025) identified 11 issues: 5 high, 3 medium, 2 low, and 1 informational.
Findings · 11
- 1 Use of Math.random for salt and password generation High
- 2 Logged-out clients can look up and trigger deletion of vaults with inactive subscriptions Informational
- 3 Variable-time comparison of secrets High
- 4 Secrets are stored in plaintext High
- 5 TOTP codes can be used multiple times High
- 6 Password reset does not require MFA authentication Medium
- 7 Fixed-password authentication allows unauthorized use of /size endpoint Low
- 8 Repository contains hard-coded credentials Medium
- 9 Deterministic encryption of file hash endangers file confidentiality Medium
- 10 General lack of cryptographic binding between file content and metadata High
- 11 The authentication protocol does not guarantee proof of possession of the vault key Low
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related
- 2026-07 MAGIC Grants Monero FCMP ++ Crypto Audit
- 2026-06 How Trail of Bits helped Turnkey build better systems Case study
- 2026-04 Ripple Labs XRP Ledger Confidential Transfer Audit
- 2026-03 Open Home Foundation SecureTar v3 Audit
- 2026-03 Anza BLS Signatures Audit
- 2026-03 HyperLink AWS Nitro TEE Audit