CVE-2025-58401: Pierre-Adrien Vasseur Obsidian GitHub Copilot Plugin
Medium severity, CVSS 5.1. EPSS: 0.1% chance of exploitation in the next 30 days.
Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.
Affected products
- Pierre-Adrien Vasseur Obsidian GitHub Copilot Plugin: before 1.1.7 (fixed in 1.1.7)
Published 2025-09-05. Last modified 2026-06-17.