


Perceptive Security
SOC/SIEM Consultancy

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can es…
Published:
26 maart 2026 om 23:00:00
Alert date:
27 maart 2026 om 23:03:46
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A cross-site scripting vulnerability in Notesnook note-taking app prior to version 3.3.11 can escalate to remote code execution in desktop applications. The vulnerability occurs in the note history comparison viewer when attacker-controlled note headers are displayed using dangerouslySetInnerHTML without proper sanitization. In the desktop version, this XSS can become RCE due to Electron's insecure configuration with nodeIntegration enabled and contextIsolation disabled. The vulnerability can be exploited through the backup and restore feature. Version 3.3.11 contains the security patch.
Technical details
Mitigation steps:
Affected products:
Notesnook
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33955
https://github.com/streetwriters/notesnook/security/advisories/GHSA-45g3-cv93-q59v
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
