PT-2026-29568 · Notesnook · Notesnook
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Notesnook versions prior to 3.3.17
Description
A stored Cross-Site Scripting (XSS) issue exists in the mobile share and web clip flow. The problem occurs because metadata from a shared clip is concatenated into HTML without proper escaping and subsequently rendered using
innerHTML within the mobile share editor WebView. An attacker can manipulate shared title metadata, such as Android/iOS share metadata (TITLE or SUBJECT) or link-preview title data, to inject malicious HTML. When a user opens the share flow and selects a Web clip, the injected payload is executed within the mobile editor WebView.Recommendations
Update to version 3.3.17.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Notesnook