top of page
perceptive_background_267k.jpg

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can es…

Published:

26 maart 2026 om 23:00:00

Alert date:

27 maart 2026 om 23:03:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A cross-site scripting vulnerability in Notesnook note-taking app prior to version 3.3.11 can escalate to remote code execution in desktop applications. The vulnerability occurs in the note history comparison viewer when attacker-controlled note headers are displayed using dangerouslySetInnerHTML without proper sanitization. In the desktop version, this XSS can become RCE due to Electron's insecure configuration with nodeIntegration enabled and contextIsolation disabled. The vulnerability can be exploited through the backup and restore feature. Version 3.3.11 contains the security patch.

Technical details

Mitigation steps:

Affected products:

Notesnook

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page