PT-2026-29568 · Notesnook · Notesnook

·

CVE-2026-33978

·

Published

2026-04-01

·

Updated

2026-04-01

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Notesnook versions prior to 3.3.17
Description A stored Cross-Site Scripting (XSS) issue exists in the mobile share and web clip flow. The problem occurs because metadata from a shared clip is concatenated into HTML without proper escaping and subsequently rendered using innerHTML within the mobile share editor WebView. An attacker can manipulate shared title metadata, such as Android/iOS share metadata (TITLE or SUBJECT) or link-preview title data, to inject malicious HTML. When a user opens the share flow and selects a Web clip, the injected payload is executed within the mobile editor WebView.
Recommendations Update to version 3.3.17.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33978
GHSA-F27J-FQC6-V7PM

Affected Products

Notesnook