Skip to main content

Obsidian Sync

Type

Security review

Client

Obsidian

Date

2025-12

Domain

Crypto

Effort

2 wks

Section

Cryptography Reviews

Trail of Bits's security review of Obsidian (Dec 2025) identified 11 issues: 5 high, 3 medium, 2 low, and 1 informational.

Findings · 11

  1. 1 Use of Math.random for salt and password generation High
  2. 2 Logged-out clients can look up and trigger deletion of vaults with inactive subscriptions Informational
  3. 3 Variable-time comparison of secrets High
  4. 4 Secrets are stored in plaintext High
  5. 5 TOTP codes can be used multiple times High
  6. 6 Password reset does not require MFA authentication Medium
  7. 7 Fixed-password authentication allows unauthorized use of /size endpoint Low
  8. 8 Repository contains hard-coded credentials Medium
  9. 9 Deterministic encryption of file hash endangers file confidentiality Medium
  10. 10 General lack of cryptographic binding between file content and metadata High
  11. 11 The authentication protocol does not guarantee proof of possession of the vault key Low

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related