Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

X4Sh3S

#47019of 53,632
5.4Total CVSS
Vulnerabilities · 1
PT-2026-24783
5.4
2026-03-11
Git · Notesnook · CVE-2026-31876
**Name of the Vulnerable Software and Affected Versions** Notesnook versions prior to 3.3.9 **Description** A Stored Cross-Site Scripting (XSS) issue existed in Notesnook’s editor embed component when processing Twitter/X embed URLs. The `tweetToEmbed()` function within `component.tsx` directly incorporated user-provided URLs into an HTML string without proper escaping before assigning it to the `srcdoc` attribute of an `<iframe>`. This allowed for the injection of malicious scripts. **Recommendations** Update Notesnook to version 3.3.9 or later.