PT-2026-28579 · Electron+1 · Electron+1

Ngocnn97

·

Publicado

2026-03-27

·

Atualizado

2026-03-28

·

CVE-2026-33955

CVSS v3.1

8.6

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notesnook versions prior to 3.3.11
Description Notesnook is a note-taking app with a cross-site scripting issue present in the note history comparison viewer on Web/Desktop platforms. This issue can lead to remote code execution in the desktop application. The issue occurs when an attacker-controlled note header is displayed using the dangerouslySetInnerHTML function without proper security measures. The desktop application's Electron configuration, with nodeIntegration set to true and contextIsolation set to false, allows for the escalation to remote code execution when combined with the full backup and restore feature. The vulnerable function is dangerouslySetInnerHTML. The vulnerable parameter is the note header.
Recommendations Update Notesnook to version 3.3.11 or later.

Exploit

Correção

RCE

Code Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33955
GHSA-45G3-CV93-Q59V

Produtos afetados

Electron
Notesnook