PT-2026-28579 · Electron+1 · Electron+1
Ngocnn97
·
Publicado
2026-03-27
·
Atualizado
2026-03-28
·
CVE-2026-33955
CVSS v3.1
8.6
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Notesnook versions prior to 3.3.11
Description
Notesnook is a note-taking app with a cross-site scripting issue present in the note history comparison viewer on Web/Desktop platforms. This issue can lead to remote code execution in the desktop application. The issue occurs when an attacker-controlled note header is displayed using the
dangerouslySetInnerHTML function without proper security measures. The desktop application's Electron configuration, with nodeIntegration set to true and contextIsolation set to false, allows for the escalation to remote code execution when combined with the full backup and restore feature. The vulnerable function is dangerouslySetInnerHTML. The vulnerable parameter is the note header.Recommendations
Update Notesnook to version 3.3.11 or later.
Exploit
Correção
RCE
Code Injection
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Electron
Notesnook