VYPR
Critical severity9.6NVD Advisory· Published Mar 27, 2026· Updated Mar 31, 2026

CVE-2026-33976

CVE-2026-33976

Description

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element and stores them inside web-clip HTML. When the clip is later opened, Notesnook renders that HTML into a same-origin, unsandboxed iframe using contentDocument.write(...). Event-handler attributes such as onload, onclick, or onmouseover execute in the Notesnook origin. In the desktop app, this becomes RCE because Electron is configured with nodeIntegration: true and contextIsolation: false. Version 3.3.11 Web/Desktop and 3.3.17 on Android/iOS patch the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:streetwriters:notesnook_desktop:*:*:*:*:*:*:*:*
    Range: <3.3.11
  • cpe:2.3:a:streetwriters:notesnook_mobile:*:*:*:*:*:android:*:*+ 2 more
    • cpe:2.3:a:streetwriters:notesnook_mobile:*:*:*:*:*:android:*:*range: <3.3.17
    • cpe:2.3:a:streetwriters:notesnook_mobile:*:*:*:*:*:iphone_os:*:*range: <3.3.17
    • (no CPE)range: <3.3.11 (Web/Desktop) and <3.3.17 (Android/iOS)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.