CVE-2026-33955Patch(streetwriters / notesnook_desktop)

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch streetwriters notesnook_desktop systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when an attacker-controlled note header is displayed using `dangerouslySetInnerHTML` without secure handling. When combined with the full backup and restore feature in the desktop application, this becomes remote code execution because Electron is configured with `nodeIntegration: true` and `contextIsolation: false`. Version 3.3.11 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • notesnook_desktop

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosures: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-27); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Products
notesnook_desktop

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-27: 2Mentions · 2026-03-28: 2Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-28: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 203-2703-28
Signal classification3 categories
Patch
250.0%
Disclosures
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-272
Disclosures1Patch1
2026-03-282
Disclosure1Patch1
Full discourse4 posts
  • NerdieNews@NewsNerdie
    Patch

    🚨 New threat alert: CVE-2026-33955 in Notesnook allows attackers to execute remote code via stored XSS in the note history viewer. This could lead to full system compromise. Patch immediately to secure your systems. #CyberSecurity #InfoSec https://t.co/5CM0WpUVHg

    Post summary

    The tweet alerts about an XSS-based RCE vulnerability (CVE‑2026‑33955) in Notesnook and urges immediate patching to prevent potential full system compromise.

    0000036
    53 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33955 Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate… https://www.cve.org/CVERecord?id=CVE-2026-33955

    Post summary

    CVE‑2026‑33955 is a stored XSS flaw in Notesnook’s note history comparison view, with no PoC, exploit code, or patch details disclosed; evidence of active exploitation is lacking.

    0000087
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33955: HIGH] Critical cyber security alert: Notesnook app prior to version 3.3.11 had a cross-site scripting vulnerability allowing remote code execution on Web/Desktop. Update to the latest versio...#cve,CVE-2026-33955,#cybersecurity https://cvefind.com/CVE-2026-33955

    Post summary

    A critical XSS vulnerability (CVE‑2026‑33955) affecting Notesnook versions prior to 3.3.11 is announced, with a remote code execution risk, and users are urged to update to the latest release for a patch.

    0000042
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosures

    🟠 CVE-2026-33955 - High Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution... https://www.thehackerwire.com/vulnerability/CVE-2026-33955/ https://t.co/xtFYLsNe2l

    Post summary

    CVE-2026-33955 is a high‑severity XSS flaw in Notesnook that can elevate to remote code execution; while technical details are present, no proof of concept, active exploitation, or patch information is cited.

    0000050
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstreetwritersnotesnook_desktop---

Explore more