CVE-2026-33976Disclosure(streetwriters / notesnook_desktop)

LOWCVSS 9.6 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch streetwriters notesnook_desktop systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element and stores them inside web-clip HTML. When the clip is later opened, Notesnook renders that HTML into a same-origin, unsandboxed iframe using `contentDocument.write(...)`. Event-handler attributes such as `onload`, `onclick`, or `onmouseover` execute in the Notesnook origin. In the desktop app, this becomes RCE because Electron is configured with `nodeIntegration: true` and `contextIsolation: false`. Version 3.3.11 Web/Desktop and 3.3.17 on Android/iOS patch the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • notesnook_desktop
  • notesnook_mobile

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-27); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
notesnook_desktopnotesnook_mobile

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Mentions · 2026-04-05: 1PoC Mentioned / Linked · 2026-03-27: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-04-05: 1Technical Details · 2026-03-27: 3Technical Details · 2026-03-28: 1Technical Details · 2026-04-05: 103-2703-2804-05
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-273
Disclosure2Patch1
2026-03-281
Disclosure1
2026-04-051
Patch1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    Dgraph patches a critical 10.0 CVSS flaw (CVE-2026-33976). Unauthenticated attackers can overwrite databases and read local files. Update to v25.3.1 now! #Dgraph #CyberSecurity #CVE202633976 #InfoSec #DatabaseSecurity #SSRF #PatchNow https://securityonline.info/dgraph-database-critical-vulnerability-cvss-10-cve-2026-33976/ https://t.co/RAVSA86K4c

    Post summary

    The tweet announces a patch for CVE‑2026‑33976, highlighting its critical severity, and directs users to update to Dgraph v25.3.1.

    05062626
    12.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33976 Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to r… https://www.cve.org/CVERecord?id=CVE-2026-33976

    Post summary

    The excerpt briefly announces a stored XSS vulnerability in Notesnook’s Web Clipper that can be escalated, without providing PoC, exploit code, or patch details.

    0000092
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33976: CRITICAL] Critical security vulnerability in Notesnook note-taking app patched in versions 3.3.11 (Web/Desktop) and 3.3.17 (Android/iOS). Update to prevent remote code execution risk.#cve,CVE-2026-33976,#cybersecurity https://cvefind.com/CVE-2026-33976

    Post summary

    The post announces a critical CVE in Notesnook and informs users that it has been patched in specific versions, with no proof of exploitation or PoC evidence presented.

    0000064
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33976 - Critical Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution ... https://www.thehackerwire.com/vulnerability/CVE-2026-33976/ https://t.co/Jbv074E8XH

    Post summary

    The post announces a critical vulnerability (CVE‑2026‑33976) affecting Notesnook, detailing a stored XSS that can be escalated to remote code execution.

    0000064
    163 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33976: Notesnook vulnerable to RCE via ... Web Clipper XSS → RCE chain hits Electron apps hard: `nodeIntegration: true` + `contextIsolation: false` = game over vi... https://zerodaysignal.com/vulnerability/CVE-2026-33976 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces that Notesnook’s Web Clipper is vulnerable to remote code execution via an XSS/chain in Electron apps, providing technical details and linking to a vulnerability report, but does not mention active exploitation, patches, or a false‑positive claim.

    0000073
    194 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appstreetwritersnotesnook_desktop---
Appstreetwritersnotesnook_mobile-android-
Appstreetwritersnotesnook_mobile-iphone_os-

Explore more