top of page
perceptive_background_267k.jpg

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can es…

Published:

26 March 2026 at 23:00:00

Alert date:

27 March 2026 at 23:03:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A cross-site scripting vulnerability in Notesnook note-taking app prior to version 3.3.11 can escalate to remote code execution in desktop applications. The vulnerability occurs in the note history comparison viewer when attacker-controlled note headers are displayed using dangerouslySetInnerHTML without proper sanitization. In the desktop version, this XSS can become RCE due to Electron's insecure configuration with nodeIntegration enabled and contextIsolation disabled. The vulnerability can be exploited through the backup and restore feature. Version 3.3.11 contains the security patch.

Technical details

Mitigation steps:

Affected products:

Notesnook

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page