PT-2026-24783 · Git+1 · Notesnook+2

·

CVE-2026-31876

·

Published

2026-03-11

·

Updated

2026-03-12

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Notesnook versions prior to 3.3.9
Description A Stored Cross-Site Scripting (XSS) issue existed in Notesnook’s editor embed component when processing Twitter/X embed URLs. The tweetToEmbed() function within component.tsx directly incorporated user-provided URLs into an HTML string without proper escaping before assigning it to the srcdoc attribute of an <iframe>. This allowed for the injection of malicious scripts.
Recommendations Update Notesnook to version 3.3.9 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31876
GHSA-JPRX-2W2H-4RH5

Affected Products

Notesnook
Notesnook Desktop
Notesnook Mobile