PT-2026-24783 · Git+1 · Notesnook+2
X4Sh3S
·
Published
2026-03-11
·
Updated
2026-03-12
·
CVE-2026-31876
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Notesnook versions prior to 3.3.9
Description
A Stored Cross-Site Scripting (XSS) issue existed in Notesnook’s editor embed component when processing Twitter/X embed URLs. The
tweetToEmbed() function within component.tsx directly incorporated user-provided URLs into an HTML string without proper escaping before assigning it to the srcdoc attribute of an <iframe>. This allowed for the injection of malicious scripts.Recommendations
Update Notesnook to version 3.3.9 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Notesnook
Notesnook Desktop
Notesnook Mobile