Skip to content

Security: initialcapacity/obsidian-html-viewer

Security

SECURITY.md

Security policy

HTML Document Viewer treats every viewed document as hostile. A report that scripts execute, remote resources load, content reaches Obsidian's DOM, or a document escapes its iframe is security-sensitive and should not be disclosed in a public issue before a fix is available.

Use the private vulnerability reporting option in the Security tab of https://github.com/initialcapacity/obsidian-html-viewer. Include the Obsidian version, platform, minimal fixture, expected result, and observed result. Remove all real vault content, credentials, tokens, and personal information.

Use GitHub Issues only for non-sensitive defects and feature requests.

There aren't any published security advisories