Critical severity9.0NVD Advisory· Published Jan 1, 2021· Updated Jun 17, 2026
CVE-2020-35717
CVE-2020-35717
Description
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- zonote/zonotedescription
Patches
Vulnerability mechanics
References
2- medium.com/bugbountywriteup/remote-code-execution-through-cross-site-scripting-in-electron-f3b891ad637nvdExploitThird Party Advisory
- www.electronjs.org/apps/zonotenvdProductThird Party Advisory
News mentions
0No linked articles in our index yet.