top of page
perceptive_background_267k.jpg

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3…

Published:

3 mei 2026 om 22:00:00

Alert date:

4 mei 2026 om 18:09:25

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Web Technologies, Enterprise Applications

A stored XSS vulnerability in Notesnook note-taking app's export flow can escalate to remote code execution in the desktop version. The vulnerability occurs when exported note fields are inserted into HTML templates without proper escaping. When exported to PDF, the HTML is rendered in an unsandboxed iframe, allowing script execution. In the desktop app, this becomes RCE due to Electron's nodeIntegration enabled and contextIsolation disabled configuration. The issue affects versions prior to Web/Desktop 3.3.15 and iOS/Android 3.3.20, and has been patched in those versions.

Technical details

Mitigation steps:

Affected products:

Notesnook

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page