Three of the four vulnerabilities remained unpatched months after OX Security reported them to the maintainers.
Hundreds of popular add‑ons used encrypted, URL‑sized payloads to send search queries, referrers, and timestamps to outside servers, in some cases tied to data brokers and unknown operators.
Five extensions were doing all sorts of malicious acts, including stealing payment data.
Obsidian is already great, but my local LLM makes it better ...