


Perceptive Security
SOC/SIEM Consultancy

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3…
Published:
3 mei 2026 om 22:00:00
Alert date:
4 mei 2026 om 18:09:25
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies, Enterprise Applications
A stored XSS vulnerability in Notesnook note-taking app's export flow can escalate to remote code execution in the desktop version. The vulnerability occurs when exported note fields are inserted into HTML templates without proper escaping. When exported to PDF, the HTML is rendered in an unsandboxed iframe, allowing script execution. In the desktop app, this becomes RCE due to Electron's nodeIntegration enabled and contextIsolation disabled configuration. The issue affects versions prior to Web/Desktop 3.3.15 and iOS/Android 3.3.20, and has been patched in those versions.
Technical details
Mitigation steps:
Affected products:
Notesnook
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42090
https://github.com/streetwriters/notesnook/releases/tag/3.3.20-android
https://github.com/streetwriters/notesnook/releases/tag/v3.3.15
https://github.com/streetwriters/notesnook/security/advisories/GHSA-fjm8-jg78-89h4
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
